MAL-2025-47417

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/web3-ws/MAL-2025-47417.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-47417
Published
2025-09-17T02:21:27Z
Modified
2025-10-27T18:09:49Z
Summary
Malicious code in web3-ws (npm)
Details

The package web3-ws was found to contain malicious code.


-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2025-05195",
            "sha256": "689f4aba1d3fb3a28c04919f292e8f90261418cf434e47e168f5e79fb70258c3",
            "modified_time": "2025-09-26T09:47:34Z",
            "versions": [
                "1.0.5"
            ],
            "import_time": "2025-09-26T11:06:07.308037734Z",
            "source": "reversing-labs"
        },
        {
            "id": "RLUA-2025-05560",
            "sha256": "6f2bdf1b6be2dbad8b09f98deab03b47e3e03e3574d2f58cdb10c35ba45e0998",
            "modified_time": "2025-10-23T19:51:08Z",
            "versions": [
                "1.0.1"
            ],
            "import_time": "2025-10-27T18:09:13.912058881Z",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

npm / web3-ws

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.1
1.0.5

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/web3-ws/MAL-2025-47417.json"