MAL-2025-6890

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hornetsecurity/angular-pew-pew/MAL-2025-6890.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-6890
Published
2025-08-16T07:10:48Z
Modified
2025-08-16T12:47:08Z
Summary
Malicious code in @hornetsecurity/angular-pew-pew (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (28e7be23ba9caf66d89c4659d66001871cf1901098bdab6dd4dd8630d476a991)

The OpenSSF Package Analysis project identified '@hornetsecurity/angular-pew-pew' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "1.0.0"
            ],
            "source": "ossf-package-analysis",
            "sha256": "28e7be23ba9caf66d89c4659d66001871cf1901098bdab6dd4dd8630d476a991",
            "import_time": "2025-08-16T07:34:47.922270891Z",
            "modified_time": "2025-08-16T07:10:48Z"
        },
        {
            "versions": [
                "1.0.3"
            ],
            "source": "ossf-package-analysis",
            "sha256": "c71531b9eb271c0664a54c1a554597c595f34745be71dc8e393b5ab518dfba64",
            "import_time": "2025-08-16T08:39:19.036317666Z",
            "modified_time": "2025-08-16T08:19:52Z"
        },
        {
            "versions": [
                "1.0.5"
            ],
            "source": "ossf-package-analysis",
            "sha256": "f8d598effec0dac5ec96a89ead0d62896c85d3007aa2991546a55ab0d03c58fc",
            "import_time": "2025-08-16T09:06:25.574303371Z",
            "modified_time": "2025-08-16T08:43:52Z"
        },
        {
            "versions": [
                "15.0.0"
            ],
            "source": "ossf-package-analysis",
            "sha256": "09864bf02710a0acda380bc7026f8dae11a139093c3884b57f1268684395ba3a",
            "import_time": "2025-08-16T12:46:47.173462995Z",
            "modified_time": "2025-08-16T12:37:16Z"
        }
    ]
}
References
Credits

Affected packages

npm / @hornetsecurity/angular-pew-pew

Package

Name
@hornetsecurity/angular-pew-pew
View open source insights on deps.dev
Purl
pkg:npm/%40hornetsecurity/angular-pew-pew

Affected ranges

Affected versions

1.*

1.0.0
1.0.3
1.0.5

15.*

15.0.0