MAL-2025-56

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@g.genie/api-demo-sample-lib4/MAL-2025-56.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-56
Published
2025-01-04T04:52:30Z
Modified
2025-01-04T04:52:30Z
Summary
Malicious code in @g.genie/api-demo-sample-lib4 (npm)
Details

This package runs commands in a pre-install script that exfils sensitive data to a attacker-controlled domain.

Database specific
{
    "malicious-packages-origins": null
}
References
Credits

Affected packages

npm / @g.genie/api-demo-sample-lib4

Package

Name
@g.genie/api-demo-sample-lib4
View open source insights on deps.dev
Purl
pkg:npm/%40g.genie/api-demo-sample-lib4

Affected ranges

Affected versions

0.*

0.3.0

1.*

1.0.1