MAL-2025-192717

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bootstrap-setcolors/MAL-2025-192717.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192717
Aliases
  • SNYK-JS-BOOTSTRAPSETCOLORS-14152232
Published
2025-12-23T08:01:18Z
Modified
2026-03-19T12:40:40.517599Z
Summary
Malicious code in bootstrap-setcolors (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (49438d0a37b288cf5dcbc9c27b5bc18510beec255d1d359a1f5a25361d4b121e)

The package bootstrap-setcolors was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2025-12-23T08:01:18Z",
            "versions": [
                "1.9.16"
            ],
            "sha256": "59e6d5d007b8f586d5586e3e623107619c77edd9ef7d12e7dab5efbb2ba03123",
            "id": "RLMA-2025-06072",
            "source": "reversing-labs",
            "import_time": "2025-12-23T16:08:07.952013947Z"
        },
        {
            "modified_time": "2025-12-24T00:41:11Z",
            "versions": [
                "1.9.16"
            ],
            "sha256": "49438d0a37b288cf5dcbc9c27b5bc18510beec255d1d359a1f5a25361d4b121e",
            "source": "amazon-inspector",
            "import_time": "2025-12-24T00:51:39.978096013Z"
        },
        {
            "modified_time": "2026-03-18T12:41:23Z",
            "sha256": "9860d258eba2d5e116ec283c8655d4d97b71bd756d0089a90e6ed2d35dca81e4",
            "id": "RLUA-2026-01130",
            "source": "reversing-labs",
            "import_time": "2026-03-19T12:20:50.318524377Z"
        }
    ]
}
References
Credits

Affected packages

npm / bootstrap-setcolors

Package

Name
bootstrap-setcolors
View open source insights on deps.dev
Purl
pkg:npm/bootstrap-setcolors

Affected ranges

Affected versions

1.*
1.9.16

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bootstrap-setcolors/MAL-2025-192717.json"