VYPR

npm · Malicious package advisory

Malware

jest-stable

MAL-2025-192678

Malicious code in jest-stable (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (d02daf523039c3df603f4e65bf270eab31b72c3d891d9be87a53c99c77950bfa)
The package jest-stable was found to contain malicious code.

## Source: ossf-package-analysis (36fdf22841fdc23172663c2bad33f8d73a6cfd02e64528502f4c1e2c43cae932)
The OpenSSF Package Analysis project identified 'jest-stable' @ 40.1.10 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

- The package executes one or more commands associated with malicious behavior.

Compromised versions (2)

  • 40.1.9
  • 40.1.10

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.