VYPR

npm · Malicious package advisory

Malware

gs-uitk-lodash

MAL-2025-192377

Malicious code in gs-uitk-lodash (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (2de2e606bc9fde8de540caf63cbded837e1bbbd7bc6bd2d477e38dcf89a76f0b)
The package gs-uitk-lodash was found to contain malicious code.

## Source: ossf-package-analysis (c89a6d85d1019b9d98f88e94d18fd4ec4ae045bd6f941941e9bdde517a749fdd)
The OpenSSF Package Analysis project identified 'gs-uitk-lodash' @ 35.3.3 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

- The package executes one or more commands associated with malicious behavior.

Compromised versions (4)

  • 35.3.3
  • 35.9.9
  • 36.0.0
  • 33.3.3

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.