MAL-2025-4933

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cmp-spid-login/MAL-2025-4933.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-4933
Published
2025-06-12T13:30:49Z
Modified
2025-06-18T01:11:33Z
Summary
Malicious code in cmp-spid-login (npm)
Details

The package communicates with a domain associated with malicious activity.


-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (f4229460b134c6c1fe4e3accbf1756e1706643a8d37bfd8a3cbe2817c11d4ced)

The OpenSSF Package Analysis project identified 'cmp-spid-login' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "ossf-package-analysis",
            "modified_time": "2025-06-12T13:36:10Z",
            "import_time": "2025-06-12T13:42:01.083057472Z",
            "versions": [
                "1.0.1"
            ],
            "sha256": "befec3c913390a465e2c602a5eed86631aa139067331f0928459d73f90a70b4c"
        },
        {
            "source": "ossf-package-analysis",
            "modified_time": "2025-06-12T13:30:49Z",
            "import_time": "2025-06-12T13:42:01.004149028Z",
            "versions": [
                "1.0.0"
            ],
            "sha256": "f4229460b134c6c1fe4e3accbf1756e1706643a8d37bfd8a3cbe2817c11d4ced"
        },
        {
            "source": "ossf-package-analysis",
            "modified_time": "2025-06-12T13:57:57Z",
            "import_time": "2025-06-12T14:05:45.642466507Z",
            "versions": [
                "1.0.4"
            ],
            "sha256": "a2249784b8388a8c2fd072eb5105f57c0be42bd6aec5bc05b218a1c9b13a0e46"
        },
        {
            "source": "ossf-package-analysis",
            "modified_time": "2025-06-12T14:55:46Z",
            "import_time": "2025-06-12T15:05:58.039692075Z",
            "versions": [
                "1.0.11"
            ],
            "sha256": "40f831870143dc7f67f95dc474b554be5d0fb17f1c1bb8ce049d17bee872ecb6"
        },
        {
            "source": "ossf-package-analysis",
            "modified_time": "2025-06-12T15:20:53Z",
            "import_time": "2025-06-12T15:37:42.057115461Z",
            "versions": [
                "1.1.1"
            ],
            "sha256": "01b0c6d43bfd54475327040e6259dc583e0aca04131d71b7cd62fd2aeb9cfde1"
        }
    ]
}
References
Credits

Affected packages

npm / cmp-spid-login

Package

Affected ranges

Type
SEMVER
Events
Introduced
1.0.0

Affected versions

1.*

1.0.0
1.0.1
1.0.4
1.0.11
1.1.1