MAL-2025-192348

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sd-notexsit/MAL-2025-192348.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192348
Published
2025-12-04T09:29:16Z
Modified
2025-12-08T03:01:55.234618Z
Summary
Malicious code in sd-notexsit (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (f4e913bd2265d51b2e2a3c9be6498c860ffc76186b24a2f81322c22d2c47a9b0)

The package sd-notexsit was found to contain malicious code.

Source: ossf-package-analysis (6af19b71c855e0821a174c728ee170ccd0e7c86e6d3f864fed1f638657ac11d9)

The OpenSSF Package Analysis project identified 'sd-notexsit' @ 999.0.41 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "f4e913bd2265d51b2e2a3c9be6498c860ffc76186b24a2f81322c22d2c47a9b0",
            "source": "amazon-inspector",
            "modified_time": "2025-12-05T21:10:10Z",
            "ranges": [
                {
                    "type": "SEMVER",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-12-05T21:36:14.910024362Z"
        },
        {
            "sha256": "6af19b71c855e0821a174c728ee170ccd0e7c86e6d3f864fed1f638657ac11d9",
            "source": "ossf-package-analysis",
            "modified_time": "2025-12-04T09:29:16Z",
            "versions": [
                "999.0.41"
            ],
            "import_time": "2025-12-08T02:39:36.970367868Z"
        }
    ]
}
References
Credits

Affected packages

npm / sd-notexsit

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

999.*
999.0.41

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sd-notexsit/MAL-2025-192348.json"