MAL-2025-191489

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/liblynxtextra.so/MAL-2025-191489.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2025-191489
Published
2025-11-29T17:45:40Z
Modified
2025-11-29T18:52:18.684149Z
Summary
Malicious code in liblynxtextra.so (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (079da6207d7932cebb243669696635a914c669cc0ccd2fe827102d11999cb226)

The OpenSSF Package Analysis project identified 'liblynxtextra.so' @ 6.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "ossf-package-analysis",
            "import_time": "2025-11-29T18:09:03.93259634Z",
            "sha256": "079da6207d7932cebb243669696635a914c669cc0ccd2fe827102d11999cb226",
            "modified_time": "2025-11-29T17:47:23Z",
            "versions": [
                "6.0.0"
            ]
        },
        {
            "source": "ossf-package-analysis",
            "import_time": "2025-11-29T18:09:04.081070152Z",
            "sha256": "17035fdbd72fa81bb14742ee263a509c6467bbecb3b0536df8fd426b190bb247",
            "modified_time": "2025-11-29T17:50:32Z",
            "versions": [
                "7.0.0"
            ]
        },
        {
            "source": "ossf-package-analysis",
            "import_time": "2025-11-29T18:09:03.736384566Z",
            "sha256": "4c72a4e3e909c9985d2d32b9a325ac46d4abb00e6a67ce8b07ebc040be4b2058",
            "modified_time": "2025-11-29T17:45:40Z",
            "versions": [
                "5.0.0"
            ]
        },
        {
            "source": "ossf-package-analysis",
            "import_time": "2025-11-29T18:41:31.224225301Z",
            "sha256": "8650f20c920c3a65cc8e4981261d94764033e62d38a14921bbe194099d2a2a4e",
            "modified_time": "2025-11-29T18:10:33Z",
            "versions": [
                "9.1.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / liblynxtextra.so

Package

Affected ranges

Affected versions

5.*

5.0.0

6.*

6.0.0

7.*

7.0.0

9.*

9.1.0