MAL-2025-192798

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/flagstealer/MAL-2025-192798.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192798
Published
2025-12-23T08:14:04Z
Modified
2025-12-24T01:10:37.855376Z
Summary
Malicious code in flagstealer (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a1f3527e4c2a632b043831e4745488a4dd8eb7df018fcfec43e89deddca6193c)

The package flagstealer was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "0.30.2",
                "0.30.4"
            ],
            "modified_time": "2025-12-23T08:14:04Z",
            "sha256": "8039d830fb8ae21bb15af693b241a4773440972a672107a37fba4344723a3991",
            "id": "RLMA-2025-06354",
            "source": "reversing-labs",
            "import_time": "2025-12-23T22:38:30.717675123Z"
        },
        {
            "versions": [
                "0.30.2",
                "0.30.4"
            ],
            "modified_time": "2025-12-24T00:41:11Z",
            "sha256": "a1f3527e4c2a632b043831e4745488a4dd8eb7df018fcfec43e89deddca6193c",
            "source": "amazon-inspector",
            "import_time": "2025-12-24T00:51:36.620814801Z"
        }
    ]
}
References
Credits

Affected packages

npm / flagstealer

Package

Affected ranges

Affected versions

0.*
0.30.2
0.30.4

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/flagstealer/MAL-2025-192798.json"