MAL-2025-9329

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@snapon/design-system-react/MAL-2025-9329.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-9329
Published
2025-08-14T18:52:04Z
Modified
2026-03-10T03:16:48.931367Z
Summary
Malicious code in @snapon/design-system-react (npm)
Details

The package @snapon/design-system-react was found to contain malicious code.


-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2025-08-28T07:15:21Z",
            "versions": [
                "1.0.0",
                "131.0.0"
            ],
            "sha256": "ef9ad92e392968e4b315c35cbcf3896b592db73c36789b2b7f05f6225a9adcf4",
            "id": "RLMA-2025-04352",
            "source": "reversing-labs",
            "import_time": "2025-08-29T06:42:04.144017889Z"
        }
    ]
}
References
Credits

Affected packages

npm / @snapon/design-system-react

Package

Name
@snapon/design-system-react
View open source insights on deps.dev
Purl
pkg:npm/%40snapon/design-system-react

Affected ranges

Affected versions

1.*
1.0.0
131.*
131.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@snapon/design-system-react/MAL-2025-9329.json"