MAL-2025-192952

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/eslint-config-sdk/MAL-2025-192952.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-192952
Published
2025-12-27T20:20:29Z
Modified
2026-03-19T12:44:04.186149Z
Summary
Malicious code in eslint-config-sdk (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e71714baca3a4619a8482f00c00fbed0efcca855796a70e740d4f53a3f807003)

The package eslint-config-sdk was found to contain malicious code.

Source: ossf-package-analysis (f555787a619d1fb5f878d4d2bc13ec29597ef72d472ef1c2897a92de23ec1662)

The OpenSSF Package Analysis project identified 'eslint-config-sdk' @ 101.0.1 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "f555787a619d1fb5f878d4d2bc13ec29597ef72d472ef1c2897a92de23ec1662",
            "modified_time": "2025-12-27T20:20:29Z",
            "versions": [
                "101.0.1"
            ],
            "import_time": "2025-12-27T20:37:59.702239224Z",
            "source": "ossf-package-analysis"
        },
        {
            "sha256": "957e494a4b9c9985c6f16f935729cea70631deadb9f0e96f5b1dfa6675dc31bb",
            "modified_time": "2025-12-28T17:25:34Z",
            "versions": [
                "101.0.4"
            ],
            "import_time": "2025-12-28T17:37:24.323029539Z",
            "source": "ossf-package-analysis"
        },
        {
            "sha256": "e71714baca3a4619a8482f00c00fbed0efcca855796a70e740d4f53a3f807003",
            "modified_time": "2026-01-02T21:29:26Z",
            "versions": [
                "101.0.1",
                "101.0.4"
            ],
            "import_time": "2026-01-02T21:35:49.047194821Z",
            "source": "amazon-inspector"
        },
        {
            "sha256": "394c5581f84c76ebac0325559f81088ed9f64d89d59c08d74ac47b4005bd3ff9",
            "modified_time": "2026-03-18T12:49:27Z",
            "id": "RLMA-2026-01296",
            "versions": [
                "1.0.0",
                "1.0.1",
                "1.1.2",
                "1.1.3",
                "99.0.0",
                "100.0.0",
                "101.0.1",
                "101.0.2",
                "101.0.3",
                "101.0.4"
            ],
            "import_time": "2026-03-19T12:18:49.982022054Z",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

npm / eslint-config-sdk

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.1.2
1.1.3
99.*
99.0.0
100.*
100.0.0
101.*
101.0.1
101.0.2
101.0.3
101.0.4

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/eslint-config-sdk/MAL-2025-192952.json"