MAL-2025-192078

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-lanternlit-sled-571/MAL-2025-192078.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192078
Published
2025-12-03T13:27:37Z
Modified
2025-12-04T00:50:05.324072Z
Summary
Malicious code in elf-stats-lanternlit-sled-571 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (4e819e445ce1152d44db7e34de5f4a1a3af115843d171802409ec55be7dc1ca7)

The package elf-stats-lanternlit-sled-571 was found to contain malicious code.

Source: ossf-package-analysis (5233cb8079c888ad1bc29ea06f89b219e5832975c3d089440def36109bf895c0)

The OpenSSF Package Analysis project identified 'elf-stats-lanternlit-sled-571' @ 9998.0.1 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "4e819e445ce1152d44db7e34de5f4a1a3af115843d171802409ec55be7dc1ca7",
            "source": "amazon-inspector",
            "modified_time": "2025-12-03T15:59:29Z",
            "versions": [
                "9998.0.1",
                "9999.0.2"
            ],
            "import_time": "2025-12-03T16:09:38.488369759Z"
        },
        {
            "sha256": "5233cb8079c888ad1bc29ea06f89b219e5832975c3d089440def36109bf895c0",
            "source": "ossf-package-analysis",
            "modified_time": "2025-12-03T13:27:37Z",
            "versions": [
                "9998.0.1"
            ],
            "import_time": "2025-12-04T00:27:05.562595513Z"
        },
        {
            "sha256": "881b5e23cb62a9a7059d5c2239ef969fba0ea3c202fd8b59bf2aba3ccfec0729",
            "source": "ossf-package-analysis",
            "modified_time": "2025-12-03T13:37:34Z",
            "versions": [
                "9999.0.2"
            ],
            "import_time": "2025-12-04T00:27:05.693882896Z"
        }
    ]
}
References
Credits

Affected packages

npm / elf-stats-lanternlit-sled-571

Package

Name
elf-stats-lanternlit-sled-571
View open source insights on deps.dev
Purl
pkg:npm/elf-stats-lanternlit-sled-571

Affected ranges

Affected versions

9998.*
9998.0.1
9999.*
9999.0.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-lanternlit-sled-571/MAL-2025-192078.json"