MAL-2025-5319

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/workflows-templates/MAL-2025-5319.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2025-5319
Published
2025-06-29T16:13:16Z
Modified
2025-07-01T14:06:28Z
Summary
Malicious code in workflows-templates (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (6135b984c29a73412cabd4922d9851440d069074d9bbe6e21e24452d9235fe87)

The OpenSSF Package Analysis project identified 'workflows-templates' @ 10.1.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-06-29T16:39:21.13805263Z",
            "source": "ossf-package-analysis",
            "versions": [
                "5.0.0"
            ],
            "sha256": "351d96ea40b31d83213985491f7c765b9ce91ac1e9728a41b3616c4e22b5ab8c",
            "modified_time": "2025-06-29T16:25:59Z"
        },
        {
            "import_time": "2025-06-29T16:39:20.982932392Z",
            "source": "ossf-package-analysis",
            "versions": [
                "2.0.0"
            ],
            "sha256": "d8297d5ca68da02a4a8d80e1eca064169903826179d4411bb261fb5034152f85",
            "modified_time": "2025-06-29T16:13:16Z"
        },
        {
            "import_time": "2025-06-29T17:04:46.415117763Z",
            "source": "ossf-package-analysis",
            "versions": [
                "5.0.1"
            ],
            "sha256": "850a1adc187e40f05d84a33ac805f057297fe76c3de032cc518711cbe5ef1e1f",
            "modified_time": "2025-06-29T16:45:57Z"
        },
        {
            "import_time": "2025-06-30T18:07:21.603598405Z",
            "source": "ossf-package-analysis",
            "versions": [
                "10.0.1"
            ],
            "sha256": "f156f51f4091507482f06343c48386939cabcbcdfc6a08ae771b748d51576831",
            "modified_time": "2025-06-30T17:50:58Z"
        },
        {
            "import_time": "2025-07-01T07:06:37.499551666Z",
            "source": "ossf-package-analysis",
            "versions": [
                "10.1.0"
            ],
            "sha256": "6135b984c29a73412cabd4922d9851440d069074d9bbe6e21e24452d9235fe87",
            "modified_time": "2025-07-01T07:05:44Z"
        },
        {
            "import_time": "2025-07-01T09:07:34.536412536Z",
            "source": "ossf-package-analysis",
            "versions": [
                "99.9.9"
            ],
            "sha256": "25b61fe89645c21ba7308eb9e7e31e3b8cf11f3709e0acac2affc7c5182bffac",
            "modified_time": "2025-07-01T09:05:15Z"
        },
        {
            "import_time": "2025-07-01T10:39:28.593967442Z",
            "source": "ossf-package-analysis",
            "versions": [
                "2.2.2"
            ],
            "sha256": "e59c98da224f58b24d0a53883c356db1626a8825bc7befb3cfe7a02f06188c92",
            "modified_time": "2025-07-01T10:35:34Z"
        },
        {
            "import_time": "2025-07-01T11:05:03.281647856Z",
            "source": "ossf-package-analysis",
            "versions": [
                "9.0.0"
            ],
            "sha256": "e15caf9fb6f02006b7d6c401e639ff1c8b6537f5b4aedf466baf5fc2496bba23",
            "modified_time": "2025-07-01T10:45:33Z"
        },
        {
            "import_time": "2025-07-01T11:05:03.384927008Z",
            "source": "ossf-package-analysis",
            "versions": [
                "20.0.0"
            ],
            "sha256": "f559b05f3d58b32d679b725967be1af976eb6721054ad91d55ac3a4f940144b4",
            "modified_time": "2025-07-01T10:50:47Z"
        },
        {
            "import_time": "2025-07-01T14:05:58.922512868Z",
            "source": "ossf-package-analysis",
            "versions": [
                "9999.9999.9999"
            ],
            "sha256": "d5ba55bd89ac3d2ca9d1ba604f3d0ffa9a8f0fac1d2c19e5604fb24b23db5302",
            "modified_time": "2025-07-01T13:56:01Z"
        }
    ]
}
References
Credits

Affected packages

npm / workflows-templates

Package

Name
workflows-templates
View open source insights on deps.dev
Purl
pkg:npm/workflows-templates

Affected ranges

Affected versions

2.*

2.0.0
2.2.2

5.*

5.0.0
5.0.1

9.*

9.0.0

10.*

10.0.1
10.1.0

20.*

20.0.0

99.*

99.9.9

9999.*

9999.9999.9999