MAL-2025-192495

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-evergreen-nightcap-747/MAL-2025-192495.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192495
Published
2025-12-11T19:46:09Z
Modified
2026-03-19T12:43:41.636680Z
Summary
Malicious code in elf-stats-evergreen-nightcap-747 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6401493011d8023c006e2f15183f09d0c1d035aa86befa459a2d5ad583cdb3e3)

The package elf-stats-evergreen-nightcap-747 was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-12-11T20:08:22.460246993Z",
            "versions": [
                "1.0.1",
                "1.0.2",
                "1.0.3",
                "1.0.0",
                "1.0.7",
                "1.0.8",
                "1.2.1",
                "1.0.9",
                "1.3.1",
                "1.4.0"
            ],
            "sha256": "6401493011d8023c006e2f15183f09d0c1d035aa86befa459a2d5ad583cdb3e3",
            "modified_time": "2025-12-11T19:46:09Z",
            "source": "amazon-inspector"
        },
        {
            "import_time": "2025-12-23T19:35:09.188738621Z",
            "versions": [
                "1.0.0",
                "1.0.1",
                "1.0.2",
                "1.0.3",
                "1.0.7",
                "1.0.8",
                "1.0.9",
                "1.2.1",
                "1.3.1",
                "1.4.0"
            ],
            "source": "reversing-labs",
            "id": "RLMA-2025-06174",
            "modified_time": "2025-12-23T08:07:29Z",
            "sha256": "231edba0315d4ffb0e7d5b4dfbb06f88dbcc93d0d93e8f1e7e498c5c181611d5"
        },
        {
            "import_time": "2026-03-19T12:20:53.506083114Z",
            "versions": [
                "2.0.0"
            ],
            "source": "reversing-labs",
            "id": "RLUA-2026-01277",
            "modified_time": "2026-03-18T12:48:37Z",
            "sha256": "f8a008db1ae27b440ffb7aa0901ffd341492ed17c14222e03d5207d667be0ce2"
        }
    ]
}
References
Credits

Affected packages

npm / elf-stats-evergreen-nightcap-747

Package

Name
elf-stats-evergreen-nightcap-747
View open source insights on deps.dev
Purl
pkg:npm/elf-stats-evergreen-nightcap-747

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.7
1.0.8
1.0.9
1.2.1
1.3.1
1.4.0
2.*
2.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/elf-stats-evergreen-nightcap-747/MAL-2025-192495.json"