MAL-2025-3935

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/eslint-plugin-i18n-strings/MAL-2025-3935.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2025-3935
Published
2025-05-18T05:48:53Z
Modified
2025-05-18T06:40:59Z
Summary
Malicious code in eslint-plugin-i18n-strings (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (dfcbe21aa41e95854f34d1d1c9398e7763b4269b08f5cb688a567848d9dc0661)

The OpenSSF Package Analysis project identified 'eslint-plugin-i18n-strings' @ 100.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "dfcbe21aa41e95854f34d1d1c9398e7763b4269b08f5cb688a567848d9dc0661",
            "import_time": "2025-05-18T06:07:55.098601187Z",
            "versions": [
                "100.0.0"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-18T05:48:53Z"
        },
        {
            "sha256": "22ab5e211b5ac67d79a904a4123f1b76996dcbd5367e44b70f0dd69866ca7117",
            "import_time": "2025-05-18T06:40:27.952294318Z",
            "versions": [
                "100.0.1"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-18T06:08:55Z"
        },
        {
            "sha256": "32571d1a8b1078c823c835a77ae282d5c74b8ac44a5d9b80647f1669a85cdee1",
            "import_time": "2025-05-18T06:40:28.088303109Z",
            "versions": [
                "100.1.2"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-18T06:19:14Z"
        },
        {
            "sha256": "996f2a02a7c48d16a4963c27903ae93669fb4513e1f51ab24b5f1c658a4de79b",
            "import_time": "2025-05-18T06:40:28.159787895Z",
            "versions": [
                "100.1.3"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-18T06:23:23Z"
        },
        {
            "sha256": "c911f0470b660323ae9bd4eb650ddeefa26aff7282158b54c10ebb8e10ef4a45",
            "import_time": "2025-05-18T06:40:28.035205484Z",
            "versions": [
                "100.1.1"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2025-05-18T06:12:18Z"
        }
    ]
}
References
Credits

Affected packages

npm / eslint-plugin-i18n-strings

Package

Name
eslint-plugin-i18n-strings
View open source insights on deps.dev
Purl
pkg:npm/eslint-plugin-i18n-strings

Affected ranges

Affected versions

100.*

100.0.0
100.0.1
100.1.1
100.1.2
100.1.3