MAL-2025-6096

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hrxtable/MAL-2025-6096.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-6096
Published
2025-07-16T13:57:37Z
Modified
2025-08-29T06:43:16Z
Summary
Malicious code in hrxtable (npm)
Details

The package communicates with a domain associated with malicious activity.


-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2025-03873",
            "import_time": "2025-08-01T10:07:18.357595235Z",
            "modified_time": "2025-07-31T19:31:54Z",
            "sha256": "b109edcd104e62df9413f44c07f555a2bc5086b9d1e88b7c07cb1a31b8e38250",
            "source": "reversing-labs",
            "versions": [
                "1.0.0",
                "1.90.0",
                "91.90.0"
            ]
        },
        {
            "id": "RLUA-2025-04557",
            "import_time": "2025-08-29T06:42:47.574815476Z",
            "modified_time": "2025-08-28T07:30:40Z",
            "sha256": "8738d4d5323d73e2c9836ff414cb46d9fd7ed7b3fff3647bd7b2ae6b713ce034",
            "source": "reversing-labs",
            "versions": [
                "100.0.0",
                "92.0.0",
                "93.0.0"
            ]
        }
    ]
}
Credits

Affected packages

npm / hrxtable

Package

Affected ranges

Type
SEMVER
Events
Introduced
91.90.0

Affected versions

1.*
1.0.0
1.90.0
91.*
91.90.0
92.*
92.0.0
93.*
93.0.0
100.*
100.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hrxtable/MAL-2025-6096.json"