MAL-2025-192812

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/jsonrecap/MAL-2025-192812.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192812
Aliases
  • SNYK-JS-JSONRECAP-14152271
Published
2025-12-23T08:18:00Z
Modified
2026-03-19T12:45:17.883188Z
Summary
Malicious code in jsonrecap (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a7e3ea65451f642ffd038933f2ca3b5dab39d6ee6979b4783353af6250dc22e9)

The package jsonrecap was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-12-24T10:07:23.973509286Z",
            "versions": [
                "3.1.8"
            ],
            "source": "reversing-labs",
            "id": "RLMA-2025-06378",
            "modified_time": "2025-12-23T08:18:00Z",
            "sha256": "0f2988a1bf0dbfd6ff12cb50f4278ad710593f273f8e6e8b594f6d95081ca1aa"
        },
        {
            "import_time": "2026-01-02T21:35:52.811798026Z",
            "versions": [
                "3.1.8"
            ],
            "sha256": "a7e3ea65451f642ffd038933f2ca3b5dab39d6ee6979b4783353af6250dc22e9",
            "modified_time": "2026-01-02T21:29:26Z",
            "source": "amazon-inspector"
        },
        {
            "import_time": "2026-03-19T12:20:55.441552276Z",
            "source": "reversing-labs",
            "id": "RLUA-2026-01378",
            "modified_time": "2026-03-18T12:56:10Z",
            "sha256": "a41d1fcb63a586513d9cca8b1183243004470500c8db731516479b0a771a3dbb"
        }
    ]
}
References
Credits

Affected packages

npm / jsonrecap

Package

Affected ranges

Affected versions

3.*
3.1.8

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/jsonrecap/MAL-2025-192812.json"