MAL-2025-585

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/diffuse-the-rest/MAL-2025-585.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-585
Published
2025-01-25T19:25:56Z
Modified
2025-01-26T02:26:50Z
Summary
Malicious code in diffuse-the-rest (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (1d6fa5846f752815846e4ce59d5326d7627b0c0ce460f8c2d36c2953b682766b)

The OpenSSF Package Analysis project identified 'diffuse-the-rest' @ 1.1.2 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-01-25T19:34:07.098701055Z",
            "versions": [
                "1.1.1"
            ],
            "sha256": "5282387e4fa57031ee7e986b7af1294a5c4185423942bac613b456e1f2ab8cf8",
            "modified_time": "2025-01-25T19:25:56Z",
            "source": "ossf-package-analysis"
        },
        {
            "import_time": "2025-01-26T02:26:30.10681735Z",
            "versions": [
                "1.1.2"
            ],
            "sha256": "1d6fa5846f752815846e4ce59d5326d7627b0c0ce460f8c2d36c2953b682766b",
            "modified_time": "2025-01-26T02:20:46Z",
            "source": "ossf-package-analysis"
        }
    ]
}
References
Credits

Affected packages

npm / diffuse-the-rest

Package

Affected ranges

Affected versions

1.*
1.1.1
1.1.2

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/diffuse-the-rest/MAL-2025-585.json"