MAL-2025-192273

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-merry-cookiejar-139/MAL-2025-192273.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192273
Published
2025-12-03T19:22:08Z
Modified
2025-12-23T21:34:52.220162Z
Summary
Malicious code in elf-stats-merry-cookiejar-139 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (3caac305a579d5472a74cce76854b64c309a81144123fd91b346199e6298009b)

The package elf-stats-merry-cookiejar-139 was found to contain malicious code.

Source: ossf-package-analysis (27114a75d7ebe496aba61de28958d2ad782d39e390996f09e0d1b29de0767253)

The OpenSSF Package Analysis project identified 'elf-stats-merry-cookiejar-139' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "amazon-inspector",
            "modified_time": "2025-12-03T19:22:08Z",
            "versions": [
                "1.0.0"
            ],
            "import_time": "2025-12-03T19:36:12.441956401Z",
            "sha256": "3caac305a579d5472a74cce76854b64c309a81144123fd91b346199e6298009b"
        },
        {
            "source": "ossf-package-analysis",
            "modified_time": "2025-12-03T19:25:38Z",
            "versions": [
                "1.0.0"
            ],
            "import_time": "2025-12-03T19:35:50.945698323Z",
            "sha256": "27114a75d7ebe496aba61de28958d2ad782d39e390996f09e0d1b29de0767253"
        },
        {
            "source": "reversing-labs",
            "id": "RLMA-2025-06227",
            "versions": [
                "1.0.0"
            ],
            "import_time": "2025-12-23T20:38:58.048141524Z",
            "sha256": "4fa053e290921c7e6c587beb3e79cb6294a9bc3a904b4f6b9f15d0f5b69e4b7c",
            "modified_time": "2025-12-23T08:08:50Z"
        }
    ]
}
References
Credits

Affected packages

npm / elf-stats-merry-cookiejar-139

Package

Name
elf-stats-merry-cookiejar-139
View open source insights on deps.dev
Purl
pkg:npm/elf-stats-merry-cookiejar-139

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-merry-cookiejar-139/MAL-2025-192273.json"