MAL-2025-192691

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cloudy-uvi-sense-v11/MAL-2025-192691.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192691
Published
2025-12-22T20:57:23Z
Modified
2025-12-22T21:51:19.472167Z
Summary
Malicious code in cloudy-uvi-sense-v11 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (ff56869fcef2b46c119633fc140a8c99af63e3e4a7e05c5e75f3fc64213dbeb2)

The package cloudy-uvi-sense-v11 was found to contain malicious code.

Source: ossf-package-analysis (5783ba00914804b5d7742c83b4fcca8675ba681434846f7cbeb118900adb7e87)

The OpenSSF Package Analysis project identified 'cloudy-uvi-sense-v11' @ 99.9.9 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-12-22T21:06:49.418367821Z",
            "modified_time": "2025-12-22T20:57:23Z",
            "source": "ossf-package-analysis",
            "versions": [
                "99.9.9"
            ],
            "sha256": "5783ba00914804b5d7742c83b4fcca8675ba681434846f7cbeb118900adb7e87"
        },
        {
            "import_time": "2025-12-22T21:36:25.318553651Z",
            "modified_time": "2025-12-22T21:23:26Z",
            "source": "amazon-inspector",
            "versions": [
                "99.9.9"
            ],
            "sha256": "ff56869fcef2b46c119633fc140a8c99af63e3e4a7e05c5e75f3fc64213dbeb2"
        }
    ]
}
References
Credits

Affected packages

npm / cloudy-uvi-sense-v11

Package

Name
cloudy-uvi-sense-v11
View open source insights on deps.dev
Purl
pkg:npm/cloudy-uvi-sense-v11

Affected ranges

Affected versions

99.*

99.9.9

Database specific

source

"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cloudy-uvi-sense-v11/MAL-2025-192691.json"