MAL-2025-5172

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/idse/MAL-2025-5172.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-5172
Published
2025-06-17T06:20:51Z
Modified
2025-06-19T01:34:39Z
Summary
Malicious code in idse (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (869cc34e50a9769a40adaa64071f9f2d1b86bd17671c26b2a790d2b72089dddf)

The OpenSSF Package Analysis project identified 'idse' @ 1.0.10 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2025-06-17T06:20:51Z",
            "versions": [
                "1.0.12"
            ],
            "sha256": "2ee877a42b576c3022a94d9f3edf402009c39d6ee448b3c08408d1668227fb40",
            "source": "ossf-package-analysis",
            "import_time": "2025-06-19T01:34:07.293914978Z"
        },
        {
            "modified_time": "2025-06-17T06:20:51Z",
            "versions": [
                "1.0.10"
            ],
            "sha256": "869cc34e50a9769a40adaa64071f9f2d1b86bd17671c26b2a790d2b72089dddf",
            "source": "ossf-package-analysis",
            "import_time": "2025-06-19T01:34:07.128279099Z"
        },
        {
            "modified_time": "2025-06-17T07:06:26Z",
            "versions": [
                "1.0.14"
            ],
            "sha256": "ba0f201a88521ced52ea91a9b2ef04956bd017087a73ef3168ac61af6902d8ce",
            "source": "ossf-package-analysis",
            "import_time": "2025-06-19T01:34:07.66267537Z"
        }
    ]
}
References
Credits

Affected packages

npm / idse

Package

Affected ranges

Affected versions

1.*
1.0.10
1.0.12
1.0.14

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/idse/MAL-2025-5172.json"