MAL-2025-192251

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-silvered-stocking-120/MAL-2025-192251.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192251
Published
2025-12-03T17:53:05Z
Modified
2025-12-24T00:23:20.701461Z
Summary
Malicious code in elf-stats-silvered-stocking-120 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (506f064ccf8457b19ab2efe04faadc4cd9eac0c263463a828646d0a3e91f6fe9)

The package elf-stats-silvered-stocking-120 was found to contain malicious code.

Source: ossf-package-analysis (4637d00550263fac9322e0e09f1d1d54c4ee545ea09e1017f46656956ce79305)

The OpenSSF Package Analysis project identified 'elf-stats-silvered-stocking-120' @ 999.0.0 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "999.0.0"
            ],
            "import_time": "2025-12-03T18:10:08.661076551Z",
            "modified_time": "2025-12-03T17:53:05Z",
            "sha256": "506f064ccf8457b19ab2efe04faadc4cd9eac0c263463a828646d0a3e91f6fe9",
            "source": "amazon-inspector"
        },
        {
            "versions": [
                "999.0.0"
            ],
            "import_time": "2025-12-04T00:27:06.306719369Z",
            "modified_time": "2025-12-03T17:57:07Z",
            "sha256": "4637d00550263fac9322e0e09f1d1d54c4ee545ea09e1017f46656956ce79305",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "999.0.0"
            ],
            "id": "RLMA-2025-06270",
            "modified_time": "2025-12-23T08:10:01Z",
            "import_time": "2025-12-23T21:06:54.626992514Z",
            "sha256": "f1eff3c5d17c143422c09c5bd9ef98792c9f651963b8feeff852bcf287ca3fc4",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

npm / elf-stats-silvered-stocking-120

Package

Name
elf-stats-silvered-stocking-120
View open source insights on deps.dev
Purl
pkg:npm/elf-stats-silvered-stocking-120

Affected ranges

Affected versions

999.*
999.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-silvered-stocking-120/MAL-2025-192251.json"