MAL-2025-6896

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/com.db.spain.common.fif.ngx-fusion-ufe/MAL-2025-6896.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-6896
Published
2025-08-18T02:47:11Z
Modified
2025-08-22T11:35:09Z
Summary
Malicious code in com.db.spain.common.fif.ngx-fusion-ufe (npm)
Details

The package communicates with a domain associated with malicious activity.


-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (30f0038c395e91d1add11ecd9f7f4784ac0fdf7c472e6ca9003c3d69ae35e031)

The OpenSSF Package Analysis project identified 'com.db.spain.common.fif.ngx-fusion-ufe' @ 2.2.8 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-08-18T03:34:43.247017676Z",
            "sha256": "30f0038c395e91d1add11ecd9f7f4784ac0fdf7c472e6ca9003c3d69ae35e031",
            "source": "ossf-package-analysis",
            "modified_time": "2025-08-18T02:55:43Z",
            "versions": [
                "2.2.8"
            ]
        },
        {
            "import_time": "2025-08-22T11:34:33.120839831Z",
            "sha256": "25be59394b178978a9e2e6bcde550023e0b20d464b555a2e5b67a9c85699665b",
            "source": "ossf-package-analysis",
            "modified_time": "2025-08-22T11:25:45Z",
            "versions": [
                "2.2.9"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / com.db.spain.common.fif.ngx-fusion-ufe

Package

Name
com.db.spain.common.fif.ngx-fusion-ufe
View open source insights on deps.dev
Purl
pkg:npm/com.db.spain.common.fif.ngx-fusion-ufe

Affected ranges

Type
SEMVER
Events
Introduced
2.2.7

Affected versions

2.*
2.2.8
2.2.9

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/com.db.spain.common.fif.ngx-fusion-ufe/MAL-2025-6896.json"