MAL-2025-192604

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xbox-bottomnav/MAL-2025-192604.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192604
Published
2025-12-17T13:15:52Z
Modified
2025-12-22T21:51:17.488872Z
Summary
Malicious code in xbox-bottomnav (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (956281b4efe244dbc01ea826196ee41b5cca6af75d50aa903ecfc4ab5bac134b)

The package xbox-bottomnav was found to contain malicious code.

Source: ossf-package-analysis (b2d3bdbb6a8dfea031f61b5a839ab2d681218a5b690455f19a91b9bd53d8f507)

The OpenSSF Package Analysis project identified 'xbox-bottomnav' @ 99.99.11 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "b2d3bdbb6a8dfea031f61b5a839ab2d681218a5b690455f19a91b9bd53d8f507",
            "source": "ossf-package-analysis",
            "modified_time": "2025-12-17T13:15:52Z",
            "versions": [
                "99.99.11"
            ],
            "import_time": "2025-12-17T13:17:52.06589243Z"
        },
        {
            "sha256": "985142080073ccd7cc475821afe7c3484755e673174b9d73accda608b2584658",
            "source": "ossf-package-analysis",
            "modified_time": "2025-12-17T14:01:16Z",
            "versions": [
                "99.99.99"
            ],
            "import_time": "2025-12-17T14:07:49.562945106Z"
        },
        {
            "sha256": "956281b4efe244dbc01ea826196ee41b5cca6af75d50aa903ecfc4ab5bac134b",
            "source": "amazon-inspector",
            "modified_time": "2025-12-22T21:23:26Z",
            "versions": [
                "99.99.11",
                "99.99.99"
            ],
            "import_time": "2025-12-22T21:36:30.481620246Z"
        }
    ]
}
References
Credits

Affected packages

npm / xbox-bottomnav

Package

Affected ranges

Affected versions

99.*
99.99.11
99.99.99

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/xbox-bottomnav/MAL-2025-192604.json"