MAL-2025-4425

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/blocks-nextjs/MAL-2025-4425.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-4425
Aliases
  • GHSA-92fg-639p-gcpp
Published
2025-05-25T18:09:30Z
Modified
2025-05-29T07:00:44Z
Summary
Malicious code in blocks-nextjs (npm)
Details

The package communicates with a domain associated with malicious activity.


-= Per source details. Do not edit below this line.=-

Source: ghsa-malware (1ae607db145f1ae39e7375c25cd19509f7f82eb76be82e74ff5cc37650ef27ba)

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Source: ossf-package-analysis (47f100e21c0ffa4aadef7d45fef11d6ed8d3c73ec4fdfb9ebb6e58178d5279d7)

The OpenSSF Package Analysis project identified 'blocks-nextjs' @ 9999.9999.10000 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "6f781ac7a0c7a0af2969d9baae513bdf2e72961846904d3595514203c2aca6da",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-25T18:18:23Z",
            "import_time": "2025-05-25T18:39:38.546077312Z",
            "versions": [
                "9999.9999.9999"
            ]
        },
        {
            "sha256": "47f100e21c0ffa4aadef7d45fef11d6ed8d3c73ec4fdfb9ebb6e58178d5279d7",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-25T18:40:59Z",
            "import_time": "2025-05-25T19:05:09.992058741Z",
            "versions": [
                "9999.9999.10000"
            ]
        },
        {
            "sha256": "5dc51c260cce872db08a00bae483f301313162b81444190c3b7f7d052c201583",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-25T19:05:49Z",
            "import_time": "2025-05-25T19:34:24.142597165Z",
            "versions": [
                "9999.9999.10002"
            ]
        },
        {
            "sha256": "aeeecae22b5e3900d19050417c36653b79c1a4e26dff1d54db88aeec6a3ac78f",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-25T19:20:05Z",
            "import_time": "2025-05-25T19:34:24.239704971Z",
            "versions": [
                "9999.9999.10004"
            ]
        },
        {
            "sha256": "122b42087386f7050e7d4d3984962b3af743ca5a159692abb78b213468833b25",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-25T19:45:37Z",
            "import_time": "2025-05-25T20:06:03.060176519Z",
            "versions": [
                "9999.9999.10005"
            ]
        },
        {
            "sha256": "4265aa9fe5e77bb087409a288a36c5b57cecbea88b6c7e1aff638b10f231306a",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T01:28:07Z",
            "import_time": "2025-05-26T01:34:55.301256212Z",
            "versions": [
                "9999.9999.10006"
            ]
        },
        {
            "sha256": "3ebdf2076e76d108daff0f3b57251b11415aa804777e7ed4ae6fbadd85669edc",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T02:22:35Z",
            "import_time": "2025-05-26T02:36:47.575103212Z",
            "versions": [
                "9999.9999.10009"
            ]
        },
        {
            "sha256": "45bfa2002e1edb894e4eb42f4b3e0b819ddcda22ad2fd722ffed2a85b563182f",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T02:04:42Z",
            "import_time": "2025-05-26T02:36:47.424726656Z",
            "versions": [
                "9999.9999.10008"
            ]
        },
        {
            "sha256": "7d3540a6720b1fdee327b3a3d5fb4dd53ba3ff9c87c6611553ac757e9b4da5fd",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T02:30:58Z",
            "import_time": "2025-05-26T02:36:47.844588378Z",
            "versions": [
                "9999.9999.10011"
            ]
        },
        {
            "sha256": "9c60debcfea079f35cfe19b7f7466030a9d133ac5d6667e6e58234f5dcc0dd8c",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T01:47:22Z",
            "import_time": "2025-05-26T02:36:47.268823463Z",
            "versions": [
                "9999.9999.10007"
            ]
        },
        {
            "sha256": "e38416e4406f42032b931ff2d29fc63094138b4777e98ed0cad77bb179f24ec0",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T02:35:53Z",
            "import_time": "2025-05-26T02:36:47.990231542Z",
            "versions": [
                "9999.9999.10012"
            ]
        },
        {
            "sha256": "ed485b999d957bc9b086ea1bda39d3908aac1cd6e8cce016c04b3c52c601ab1d",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T02:22:46Z",
            "import_time": "2025-05-26T02:36:47.722359976Z",
            "versions": [
                "9999.9999.10010"
            ]
        },
        {
            "sha256": "5022c44e0c71527c0aac0f48b127f1ebc53f1f7ba645243dccf77dfa1eb0a116",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T03:10:57Z",
            "import_time": "2025-05-26T03:27:06.751452697Z",
            "versions": [
                "9999.9999.10015"
            ]
        },
        {
            "sha256": "70c88fddcd23c674401a94c2e5d15faee6df5b6bf9361adc32ce61d2f1ad1dac",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T03:29:31Z",
            "import_time": "2025-05-26T03:48:31.080672029Z",
            "versions": [
                "9999.9999.10016"
            ]
        },
        {
            "sha256": "a692171833a566b9c692e5585c70f2a9ffdd3abc181c8876d08f4edd05ff4825",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T13:55:58Z",
            "import_time": "2025-05-26T14:06:36.066625606Z",
            "versions": [
                "9999.9999.10020"
            ]
        },
        {
            "sha256": "dc0060ac9875771b776cc18731be0bc661b1c253ec85a3587a045934f88853b4",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T14:26:05Z",
            "import_time": "2025-05-26T14:38:42.407159104Z",
            "versions": [
                "9999.9999.10023"
            ]
        },
        {
            "sha256": "1f4c5ac0da34f9ee3462adc8dbd399159987880b873655ba93be0d332b39d392",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T19:55:50Z",
            "import_time": "2025-05-26T20:06:32.524277244Z",
            "versions": [
                "9999.9999.10029"
            ]
        },
        {
            "sha256": "26dc6ca1b00248714f3fb24fc89a8a9ec5ec001295dff2ebf29456b246a52532",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T19:45:40Z",
            "import_time": "2025-05-26T20:06:32.355293918Z",
            "versions": [
                "9999.9999.10026"
            ]
        },
        {
            "sha256": "2e23ece37030fb9cd3492271ee0bb58a59cf92c370e1306c256547f428a30abb",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T19:50:42Z",
            "import_time": "2025-05-26T20:06:32.423441186Z",
            "versions": [
                "9999.9999.10027"
            ]
        },
        {
            "sha256": "495500035d4eb39dc395338f1046862d3f0a05cc7de3f12b3d0697769a994db8",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T20:05:56Z",
            "import_time": "2025-05-26T20:06:32.745990817Z",
            "versions": [
                "9999.9999.10032"
            ]
        },
        {
            "sha256": "b3a914885837f9f5ac4b92aa878c4e6ddb07bb5f5aa548fda99e564d0abe6369",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T20:00:52Z",
            "import_time": "2025-05-26T20:06:32.616049708Z",
            "versions": [
                "9999.9999.10030"
            ]
        },
        {
            "sha256": "fc25a00422fc439589231b1a3f39069f047eae43b579011b00ab67954c2af508",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T19:39:26Z",
            "import_time": "2025-05-26T20:06:32.274162236Z",
            "versions": [
                "9999.9999.10025"
            ]
        },
        {
            "sha256": "6c64bc21251c578141e81a4330ca9d2b1e3c520621a72b3804c4419f22e1e1e6",
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-26T20:10:49Z",
            "import_time": "2025-05-26T20:36:37.438122867Z",
            "versions": [
                "9999.9999.10034"
            ]
        },
        {
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "SEMVER"
                }
            ],
            "sha256": "1ae607db145f1ae39e7375c25cd19509f7f82eb76be82e74ff5cc37650ef27ba",
            "id": "GHSA-92fg-639p-gcpp",
            "modified_time": "2025-05-28T05:55:18Z",
            "import_time": "2025-05-29T00:37:32.959455678Z",
            "source": "ghsa-malware"
        }
    ]
}
References
Credits

Affected packages

npm / blocks-nextjs

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Type
SEMVER
Events
Introduced
9999.9999.9999

Affected versions

9999.*

9999.9999.9999
9999.9999.10000
9999.9999.10002
9999.9999.10004
9999.9999.10005
9999.9999.10006
9999.9999.10007
9999.9999.10008
9999.9999.10009
9999.9999.10010
9999.9999.10011
9999.9999.10012
9999.9999.10015
9999.9999.10016
9999.9999.10020
9999.9999.10023
9999.9999.10025
9999.9999.10026
9999.9999.10027
9999.9999.10029
9999.9999.10030
9999.9999.10032
9999.9999.10034

Database specific

{
    "cwes": [
        {
            "name": "Embedded Malicious Code",
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature."
        }
    ]
}