Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
MAL-2025-40664
See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/yup-latest/MAL-2025-40664.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-40664
Published
2025-08-14T18:52:04Z
Modified
2025-08-14T18:52:04Z
Summary
Malicious code in yup-latest (npm)
Details
The package yup-latest was found to contain malicious code.
Database specific
{ "malicious-packages-origins": null }
References
Credits
Amazon Inspector - FINDER
actran@amazon.com
Affected packages
npm
/
yup-latest
Package
Name
yup-latest
View open source insights on deps.dev
Purl
pkg:npm/yup-latest
Affected ranges
Type
SEMVER
Events
Introduced
0
Unknown introduced version / All previous versions are affected
MAL-2025-40664 - OSV