MAL-2025-192855

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-flex-tools/MAL-2025-192855.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192855
Aliases
  • SNYK-JS-REACTFLEXTOOLS-14152285
Published
2025-12-23T08:26:31Z
Modified
2026-03-19T12:47:38.559478Z
Summary
Malicious code in react-flex-tools (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (1ab5b4a0a39a8b9ccc5dd27ea7207f3006128207203ee8ceb99dbef4be0ec9d3)

The package react-flex-tools was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "2.0.1"
            ],
            "modified_time": "2025-12-23T08:26:31Z",
            "sha256": "2e340363a8999fa89f8f3ad5ea5318c4d32edd746aa2d80f4f89da2b1b69fd94",
            "id": "RLMA-2025-06457",
            "source": "reversing-labs",
            "import_time": "2025-12-24T10:07:26.824831642Z"
        },
        {
            "versions": [
                "2.0.1"
            ],
            "modified_time": "2026-01-02T21:29:26Z",
            "sha256": "1ab5b4a0a39a8b9ccc5dd27ea7207f3006128207203ee8ceb99dbef4be0ec9d3",
            "source": "amazon-inspector",
            "import_time": "2026-01-02T21:35:53.094030078Z"
        },
        {
            "modified_time": "2026-03-18T13:06:11Z",
            "sha256": "bc0a8579ece68eb524c896cf4694565f937a05bdb5a8c9a9927dc526accbc625",
            "id": "RLUA-2026-01527",
            "source": "reversing-labs",
            "import_time": "2026-03-19T12:20:57.64902498Z"
        }
    ]
}
References
Credits

Affected packages

npm / react-flex-tools

Package

Affected ranges

Affected versions

2.*
2.0.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-flex-tools/MAL-2025-192855.json"