MAL-2025-48708

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ldhemrdhs92007/MAL-2025-48708.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-48708
Published
2025-10-26T19:03:27Z
Modified
2025-12-02T10:10:19.382551Z
Summary
Malicious code in ldhemrdhs92007 (npm)
Details

The package ldhemrdhs92007 was found to contain malicious code.


-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-12-02T09:09:49.723475273Z",
            "modified_time": "2025-12-01T13:15:26Z",
            "source": "reversing-labs",
            "sha256": "f0684ca05cb2bc623eff36c4ac08d1aa063e1fe0ae77555df6ab00d85cb7404b",
            "id": "RLMA-2025-05837",
            "versions": [
                "1.250701.10924",
                "1.250701.10929",
                "1.250701.10934",
                "1.250701.10939",
                "1.250701.11042",
                "1.250701.11128",
                "1.250701.11132",
                "1.250701.11259",
                "1.250710.10939",
                "1.250712.11516",
                "1.250712.11555",
                "1.250713.11253",
                "1.250713.11401",
                "1.250714.10940",
                "1.250724.11109",
                "1.250724.11113",
                "1.250725.12014",
                "1.250726.10029",
                "1.250726.10814",
                "1.250726.11020",
                "1.250726.11709",
                "1.250726.11745",
                "1.250727.11906",
                "1.250728.12157",
                "1.250729.11526",
                "1.250730.11438",
                "1.250731.11126",
                "1.250731.11131",
                "1.250731.11135",
                "1.250731.11139",
                "1.250731.11144",
                "1.250731.11345",
                "1.250731.11417",
                "1.250731.11432",
                "1.250801.11452",
                "1.250801.11550",
                "1.250801.11732",
                "1.250801.12029",
                "1.250805.11142",
                "1.250805.11403",
                "1.250805.11851",
                "1.250805.12016",
                "1.250806.10825",
                "1.250806.10944",
                "1.250806.10947",
                "1.250806.11410",
                "1.250806.11422",
                "1.250806.11447",
                "1.250806.11549",
                "1.250807.11035",
                "1.250808.11108",
                "1.250808.11426",
                "1.250808.11442",
                "1.250808.11509",
                "1.250808.12106",
                "1.250809.11028",
                "1.250809.11715",
                "1.250810.11940",
                "1.250810.12016",
                "1.250811.12053",
                "1.250811.12107",
                "1.250812.11105",
                "1.250812.11111",
                "1.250814.11124",
                "1.250814.11833",
                "1.250814.11914",
                "1.250817.11654",
                "1.250819.11906",
                "1.250820.10848",
                "1.250820.10852",
                "1.250820.10911",
                "1.250820.10921",
                "1.250820.10926",
                "1.250820.10929",
                "1.250820.11314",
                "1.250820.11324",
                "1.250820.11334",
                "1.250820.11958",
                "1.250821.11346",
                "1.250821.11923",
                "1.250822.10945",
                "1.250822.11140",
                "1.250829.11329",
                "1.250829.11355",
                "1.250829.11408",
                "1.250905.11009",
                "1.250905.11020",
                "1.251009.11018"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / ldhemrdhs92007

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.250701.10924
1.250701.10929
1.250701.10934
1.250701.10939
1.250701.11042
1.250701.11128
1.250701.11132
1.250701.11259
1.250710.10939
1.250712.11516
1.250712.11555
1.250713.11253
1.250713.11401
1.250714.10940
1.250724.11109
1.250724.11113
1.250725.12014
1.250726.10029
1.250726.10814
1.250726.11020
1.250726.11709
1.250726.11745
1.250727.11906
1.250728.12157
1.250729.11526
1.250730.11438
1.250731.11126
1.250731.11131
1.250731.11135
1.250731.11139
1.250731.11144
1.250731.11345
1.250731.11417
1.250731.11432
1.250801.11452
1.250801.11550
1.250801.11732
1.250801.12029
1.250805.11142
1.250805.11403
1.250805.11851
1.250805.12016
1.250806.10825
1.250806.10944
1.250806.10947
1.250806.11410
1.250806.11422
1.250806.11447
1.250806.11549
1.250807.11035
1.250808.11108
1.250808.11426
1.250808.11442
1.250808.11509
1.250808.12106
1.250809.11028
1.250809.11715
1.250810.11940
1.250810.12016
1.250811.12053
1.250811.12107
1.250812.11105
1.250812.11111
1.250814.11124
1.250814.11833
1.250814.11914
1.250817.11654
1.250819.11906
1.250820.10848
1.250820.10852
1.250820.10911
1.250820.10921
1.250820.10926
1.250820.10929
1.250820.11314
1.250820.11324
1.250820.11334
1.250820.11958
1.250821.11346
1.250821.11923
1.250822.10945
1.250822.11140
1.250829.11329
1.250829.11355
1.250829.11408
1.250905.11009
1.250905.11020
1.251009.11018

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ldhemrdhs92007/MAL-2025-48708.json"