MAL-2025-3957

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/vscode-oja/MAL-2025-3957.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-3957
Published
2025-05-18T20:58:50Z
Modified
2025-05-19T00:26:50Z
Summary
Malicious code in vscode-oja (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (222332856f685e334465b24346da36177ea57028e903aaf5c7b6fc845f1e601a)

The OpenSSF Package Analysis project identified 'vscode-oja' @ 100.0.2 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-05-19T00:26:17.369870469Z",
            "source": "ossf-package-analysis",
            "versions": [
                "100.0.2"
            ],
            "modified_time": "2025-05-18T20:58:50Z",
            "sha256": "222332856f685e334465b24346da36177ea57028e903aaf5c7b6fc845f1e601a"
        },
        {
            "import_time": "2025-05-19T00:26:18.177299953Z",
            "source": "ossf-package-analysis",
            "versions": [
                "100.0.3"
            ],
            "modified_time": "2025-05-18T22:22:19Z",
            "sha256": "9eaf3237357312dc7f31e524faed9e1e421b40d5310d785839bc8b5ea51ffef1"
        }
    ]
}
References
Credits

Affected packages

npm / vscode-oja

Package

Affected ranges

Affected versions

100.*

100.0.2
100.0.3