MAL-2025-4149

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@ctg-ui/web-shell-express/MAL-2025-4149.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-4149
Published
2025-05-22T12:34:41Z
Modified
2025-05-22T12:34:41Z
Summary
Malicious code in @ctg-ui/web-shell-express (npm)
Details

-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "reversing-labs",
            "modified_time": "2025-05-22T12:34:41Z",
            "sha256": "4b49500ed85885d6ec0eedca83428a9342821c485d8c930c348b995cdc5bab1f",
            "versions": [
                "1.0.0",
                "10.1.0"
            ],
            "id": "RLMA-2025-02639",
            "import_time": "2025-05-22T14:06:41.363824405Z"
        }
    ]
}
References
Credits

Affected packages

npm / @ctg-ui/web-shell-express

Package

Name
@ctg-ui/web-shell-express
View open source insights on deps.dev
Purl
pkg:npm/%40ctg-ui/web-shell-express

Affected ranges

Affected versions

1.*

1.0.0

10.*

10.1.0