MAL-2025-48555

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/user_oidc/MAL-2025-48555.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-48555
Aliases
  • GHSA-xc3q-j43c-38v2
Published
2025-10-22T02:13:41Z
Modified
2025-10-24T02:12:43.584259Z
Summary
Malicious code in user_oidc (npm)
Details

The package communicates with a domain associated with malicious activity.


-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (e28e6e5435f54199a3dca6186e1ad2d2846226bcf0a6792ff09d40b6215ed7af)

The OpenSSF Package Analysis project identified 'user_oidc' @ 8.0.2 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-10-22T23:05:36.182329804Z",
            "source": "ossf-package-analysis",
            "versions": [
                "8.0.2"
            ],
            "modified_time": "2025-10-22T22:40:50Z",
            "sha256": "e28e6e5435f54199a3dca6186e1ad2d2846226bcf0a6792ff09d40b6215ed7af"
        },
        {
            "import_time": "2025-10-23T15:06:43.7752139Z",
            "source": "ossf-package-analysis",
            "versions": [
                "8.0.3"
            ],
            "modified_time": "2025-10-23T14:43:46Z",
            "sha256": "c735f97412c53181c344dda45b28cfe8f99d2125683693c3d097dc15722f76b3"
        },
        {
            "id": "GHSA-xc3q-j43c-38v2",
            "import_time": "2025-10-24T01:52:31.545667029Z",
            "source": "ghsa-malware",
            "ranges": [
                {
                    "type": "SEMVER",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "modified_time": "2025-10-24T01:36:04Z",
            "sha256": "ab3ebb3b9bc178d18b199897b5d5d0492737f9ce310613487f3bd3e1278b086e"
        }
    ]
}
References
Credits

Affected packages

npm / user_oidc

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*
8.0.2
8.0.3

Database specific

cwes
[
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/user_oidc/MAL-2025-48555.json"