MAL-2025-4751

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/moonpay-demo-integrations/MAL-2025-4751.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-4751
Published
2025-06-05T15:20:23Z
Modified
2025-06-18T15:07:35Z
Summary
Malicious code in moonpay-demo-integrations (npm)
Details

The package communicates with a domain associated with malicious activity.


-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2025-06-18T10:34:14Z",
            "id": "RLMA-2025-03327",
            "source": "reversing-labs",
            "versions": [
                "0.0.1",
                "0.1.0",
                "1.0.0"
            ],
            "import_time": "2025-06-18T15:06:28.428500111Z",
            "sha256": "b936e5df92f7ec2b12cb094824f3104b297d89aae1c610b7ec072eb1388cecb6"
        }
    ]
}
References
Credits

Affected packages

npm / moonpay-demo-integrations

Package

Name
moonpay-demo-integrations
View open source insights on deps.dev
Purl
pkg:npm/moonpay-demo-integrations

Affected ranges

Type
SEMVER
Events
Introduced
1.0.0

Affected versions

0.*

0.0.1
0.1.0

1.*

1.0.0