MAL-2025-191982

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-ginger-hammer-326/MAL-2025-191982.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-191982
Published
2025-12-03T14:30:46Z
Modified
2025-12-23T20:50:24.493891Z
Summary
Malicious code in elf-stats-ginger-hammer-326 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (b381aa5a37f1282740de384eeff72f5f4d3e57918e530d486989909249b8c821)

The package elf-stats-ginger-hammer-326 was found to contain malicious code.

Source: ossf-package-analysis (ab28db009d546523ca9bfce3468ed5b176df45db15f988ba15d36c0d6a6e7151)

The OpenSSF Package Analysis project identified 'elf-stats-ginger-hammer-326' @ 1.0.3 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-12-03T14:41:00.206381013Z",
            "sha256": "ab28db009d546523ca9bfce3468ed5b176df45db15f988ba15d36c0d6a6e7151",
            "source": "ossf-package-analysis",
            "modified_time": "2025-12-03T14:30:46Z",
            "versions": [
                "1.0.3"
            ]
        },
        {
            "import_time": "2025-12-03T16:09:54.971226758Z",
            "sha256": "b381aa5a37f1282740de384eeff72f5f4d3e57918e530d486989909249b8c821",
            "source": "amazon-inspector",
            "modified_time": "2025-12-03T15:59:29Z",
            "versions": [
                "2.0.1",
                "1.0.3",
                "1.0.4"
            ]
        },
        {
            "id": "RLMA-2025-06199",
            "import_time": "2025-12-23T20:07:22.58575325Z",
            "sha256": "d977698543c6266094eecdd8817ba371e26077dd7faece69c4fe4c4a07ff32b0",
            "source": "reversing-labs",
            "modified_time": "2025-12-23T08:08:02Z",
            "versions": [
                "2.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / elf-stats-ginger-hammer-326

Package

Name
elf-stats-ginger-hammer-326
View open source insights on deps.dev
Purl
pkg:npm/elf-stats-ginger-hammer-326

Affected ranges

Affected versions

1.*
1.0.3
1.0.4
2.*
2.0.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-ginger-hammer-326/MAL-2025-191982.json"