VYPR

npm · Malicious package advisory

Malware

elf-stats-merry-garland-548

MAL-2025-192201

Malicious code in elf-stats-merry-garland-548 (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (f5b0446bc7b428d52a072e60b18969e2e9b35f19d70d6a77bc8176e76dd14506)
The package elf-stats-merry-garland-548 was found to contain malicious code.

## Source: ossf-package-analysis (03708b81d9c3c399b037b2d76317b4259fff76f0b4fb9f6e6472226d89698749)
The OpenSSF Package Analysis project identified 'elf-stats-merry-garland-548' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

Compromised versions (3)

  • 1.0.0
  • 1.0.1
  • 1.0.2

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.