MAL-2025-19729

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/epxresso/MAL-2025-19729.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-19729
Aliases
  • SNYK-JS-EPXRESSO-13561256
Published
2025-08-14T18:52:04Z
Modified
2025-12-02T10:14:45.951284Z
Summary
Malicious code in epxresso (npm)
Details

The package epxresso was found to contain malicious code.


-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-08-29T06:42:20.299087706Z",
            "modified_time": "2025-08-28T07:27:23Z",
            "source": "reversing-labs",
            "sha256": "a4e189cbdba808b8cf52ec2f0bb137bebf0aa30e83f768486b0baae6154ee398",
            "id": "RLMA-2025-04511",
            "versions": [
                "5.1.0",
                "5.1.1",
                "5.1.2",
                "5.1.3"
            ]
        },
        {
            "import_time": "2025-12-02T09:10:04.031733605Z",
            "modified_time": "2025-12-01T13:09:47Z",
            "source": "reversing-labs",
            "sha256": "78743035bbaca745b03d0af646c055eb7ea169da0c2e6766a1edcf31721ea47e",
            "id": "RLUA-2025-05780"
        }
    ]
}
References
Credits

Affected packages

npm / epxresso

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.1.0
5.1.1
5.1.2
5.1.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/epxresso/MAL-2025-19729.json"