npm · Malicious package advisory
Malwarejsondatatoruby
MAL-2025-192584
Malicious code in jsondatatoruby (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (89f78392e9a3a510c3e509f058c49aff59b8b98fff6beca0f5f30bbb8e85a9bd) The package jsondatatoruby was found to contain malicious code. ## Source: ossf-package-analysis (baeae2c02ab89a72cdfb758215138d1c6ec321ee3c17535b0f2cbe54a341784d) The OpenSSF Package Analysis project identified 'jsondatatoruby' @ 1.999.10 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.
Compromised versions (2)
- 1.999.1
- 1.999.10
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.