MAL-2025-49395

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@deputyapp/copilot2/MAL-2025-49395.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-49395
Published
2025-11-09T00:17:09Z
Modified
2025-12-23T15:48:14.419258Z
Summary
Malicious code in @deputyapp/copilot2 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (ea8ee55f0fba70e99bcfd17466e3bb1bf57b3bbdd3e6f7a61a54673d0b78aff5)

The package @deputyapp/copilot2 was found to contain malicious code.

Source: ossf-package-analysis (e4d87eb825013bd349713caf54711ff430c5f1bb476da6fb634734af796b0108)

The OpenSSF Package Analysis project identified '@deputyapp/copilot2' @ 2.10.20 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "ea8ee55f0fba70e99bcfd17466e3bb1bf57b3bbdd3e6f7a61a54673d0b78aff5",
            "ranges": [
                {
                    "type": "SEMVER",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "import_time": "2025-11-09T00:27:25.057620796Z",
            "source": "amazon-inspector",
            "modified_time": "2025-11-09T00:17:09Z"
        },
        {
            "sha256": "e4d87eb825013bd349713caf54711ff430c5f1bb476da6fb634734af796b0108",
            "versions": [
                "2.10.20"
            ],
            "import_time": "2025-11-16T15:05:55.978858956Z",
            "source": "ossf-package-analysis",
            "modified_time": "2025-11-16T15:00:13Z"
        },
        {
            "modified_time": "2025-12-23T07:45:35Z",
            "sha256": "3a8b1425316e6756dbfd81008289ba03def855beee0b0f391ca91c98a1907ab1",
            "versions": [
                "2.9.9",
                "2.10.11",
                "2.10.20"
            ],
            "import_time": "2025-12-23T15:07:37.667061967Z",
            "source": "reversing-labs",
            "id": "RLMA-2025-06017"
        }
    ]
}
References
Credits

Affected packages

npm / @deputyapp/copilot2

Package

Name
@deputyapp/copilot2
View open source insights on deps.dev
Purl
pkg:npm/%40deputyapp/copilot2

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.9.9
2.10.11
2.10.20

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@deputyapp/copilot2/MAL-2025-49395.json"