MAL-2025-48556

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/qwant-search-extension/MAL-2025-48556.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-48556
Aliases
  • GHSA-ghr2-6g4g-94h5
Published
2025-10-21T17:35:33Z
Modified
2025-10-24T02:12:43.370199Z
Summary
Malicious code in qwant-search-extension (npm)
Details

The package communicates with a domain associated with malicious activity.


-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (b62fa18764e78b78ad37bea56c978df2cba57aa015e3b3eb13b0fc74e05678b1)

The OpenSSF Package Analysis project identified 'qwant-search-extension' @ 10.0.6 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "b62fa18764e78b78ad37bea56c978df2cba57aa015e3b3eb13b0fc74e05678b1",
            "source": "ossf-package-analysis",
            "modified_time": "2025-10-23T00:01:16Z",
            "versions": [
                "10.0.6"
            ],
            "import_time": "2025-10-23T00:24:02.612457958Z"
        },
        {
            "sha256": "fc6266d12cc5a5fde2751cbbd5120927324224297ca596759dbfa5abbc08c1c6",
            "source": "ghsa-malware",
            "modified_time": "2025-10-24T01:35:59Z",
            "id": "GHSA-ghr2-6g4g-94h5",
            "ranges": [
                {
                    "type": "SEMVER",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-10-24T01:52:31.542759815Z"
        }
    ]
}
References
Credits

Affected packages

npm / qwant-search-extension

Package

Name
qwant-search-extension
View open source insights on deps.dev
Purl
pkg:npm/qwant-search-extension

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

10.*
10.0.6

Database specific

cwes
[
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/qwant-search-extension/MAL-2025-48556.json"