MAL-2025-192883

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/varshade-afc/MAL-2025-192883.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192883
Published
2025-12-23T08:34:50Z
Modified
2026-01-02T22:04:46.011564Z
Summary
Malicious code in varshade-afc (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (8c090ef4ab6892af3d5f4b03ce4af456c7a50f5aa6411bfe1644ce3772a2407c)

The package varshade-afc was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-12-24T10:07:29.333989375Z",
            "modified_time": "2025-12-23T08:34:50Z",
            "source": "reversing-labs",
            "sha256": "048dd8a21e015013e0fd38cbbccd515dcbd5a390dade56238d7a7a58fc533fda",
            "id": "RLMA-2025-06522",
            "versions": [
                "4.6.14",
                "4.6.15",
                "4.6.16",
                "4.6.17",
                "4.6.18"
            ]
        },
        {
            "import_time": "2026-01-02T21:35:54.074395125Z",
            "modified_time": "2026-01-02T21:29:26Z",
            "source": "amazon-inspector",
            "sha256": "8c090ef4ab6892af3d5f4b03ce4af456c7a50f5aa6411bfe1644ce3772a2407c",
            "versions": [
                "4.6.14",
                "4.6.15",
                "4.6.16",
                "4.6.17",
                "4.6.18"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / varshade-afc

Package

Affected ranges

Affected versions

4.*
4.6.14
4.6.15
4.6.16
4.6.17
4.6.18

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/varshade-afc/MAL-2025-192883.json"