MAL-2025-4709

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/arc-offsec-custom-library6/MAL-2025-4709.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-4709
Published
2025-06-06T08:14:06Z
Modified
2025-06-06T09:37:15Z
Summary
Malicious code in arc-offsec-custom-library6 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (6a8ca75cc8c3631c7dee6f43572f347eb27f678db568e8b0b2c0173fc47f4e06)

The OpenSSF Package Analysis project identified 'arc-offsec-custom-library6' @ 1.0.7-x (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "535ecaf735b31484a870e2b44f27ab845611d9ef183edea1a8bb8b69ebd9d497",
            "import_time": "2025-06-06T08:39:33.220413439Z",
            "versions": [
                "1.1.0"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-06-06T08:14:06Z"
        },
        {
            "sha256": "6a8ca75cc8c3631c7dee6f43572f347eb27f678db568e8b0b2c0173fc47f4e06",
            "import_time": "2025-06-06T08:39:33.293923424Z",
            "versions": [
                "1.0.7-x"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-06-06T08:18:11Z"
        },
        {
            "sha256": "7f48a04a3b9d9792352fcdc5330fa7dae8a3b9ebac93a4f8432804cfb4005d0f",
            "import_time": "2025-06-06T08:39:33.366675874Z",
            "versions": [
                "1.0.8"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-06-06T08:28:44Z"
        },
        {
            "sha256": "6b9554505d4ce96ca0f89a5d017549d3fc06a5621dfeb6438e422a1e219bbd14",
            "import_time": "2025-06-06T09:36:35.205126981Z",
            "versions": [
                "1.1.1"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-06-06T09:26:02Z"
        }
    ]
}
References
Credits

Affected packages

npm / arc-offsec-custom-library6

Package

Name
arc-offsec-custom-library6
View open source insights on deps.dev
Purl
pkg:npm/arc-offsec-custom-library6

Affected ranges

Affected versions

1.*

1.0.7-x
1.0.8
1.1.0
1.1.1