MAL-2025-3031

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/one-venafi-local-store-manager/MAL-2025-3031.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-3031
Published
2025-04-02T17:40:46Z
Modified
2025-04-02T18:40:58Z
Summary
Malicious code in one-venafi-local-store-manager (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (6368f9d9802e4cee726a0e6cb5adae6d8a31d8ce4cea0d6d515fcb9077d2f220)

The OpenSSF Package Analysis project identified 'one-venafi-local-store-manager' @ 1.0.8 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "6368f9d9802e4cee726a0e6cb5adae6d8a31d8ce4cea0d6d515fcb9077d2f220",
            "import_time": "2025-04-02T18:07:26.899966099Z",
            "versions": [
                "1.0.8"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-04-02T17:55:55Z"
        },
        {
            "sha256": "b95de0e8e7bda81c1cd85ec86bd2cbde03b9e970c7a09292d1efed528eb38f59",
            "import_time": "2025-04-02T18:07:26.840096991Z",
            "versions": [
                "1.0.3"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-04-02T17:40:46Z"
        },
        {
            "sha256": "2402a7df0fb144042dcc65e036698bf145672a47bcc29d6fc953a4fa5c6d8d65",
            "import_time": "2025-04-02T18:40:24.18796226Z",
            "versions": [
                "1.0.9"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-04-02T18:10:55Z"
        }
    ]
}
References
Credits

Affected packages

npm / one-venafi-local-store-manager

Package

Name
one-venafi-local-store-manager
View open source insights on deps.dev
Purl
pkg:npm/one-venafi-local-store-manager

Affected ranges

Affected versions

1.*

1.0.3
1.0.8
1.0.9