MAL-2025-6865

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/azure-documentdb-node/MAL-2025-6865.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-6865
Published
2025-08-13T13:59:25Z
Modified
2025-08-17T10:06:30Z
Summary
Malicious code in azure-documentdb-node (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (6ae212af083dc32114fe6584d59ab57ac5b5c3b77d59d83cd62af05f8706cdf0)

The OpenSSF Package Analysis project identified 'azure-documentdb-node' @ 9.9.9 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "6ae212af083dc32114fe6584d59ab57ac5b5c3b77d59d83cd62af05f8706cdf0",
            "source": "ossf-package-analysis",
            "modified_time": "2025-08-13T13:59:25Z",
            "versions": [
                "9.9.9"
            ],
            "import_time": "2025-08-13T14:07:05.016124488Z"
        },
        {
            "sha256": "78e70cb28907b4624ee198d76840c92eaea8fe38caadfb148bd7867b27985e3a",
            "source": "ossf-package-analysis",
            "modified_time": "2025-08-17T09:47:55Z",
            "versions": [
                "9.9.2"
            ],
            "import_time": "2025-08-17T10:06:05.682847596Z"
        }
    ]
}
References
Credits

Affected packages

npm / azure-documentdb-node

Package

Name
azure-documentdb-node
View open source insights on deps.dev
Purl
pkg:npm/azure-documentdb-node

Affected ranges

Affected versions

9.*
9.9.2
9.9.9

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/azure-documentdb-node/MAL-2025-6865.json"