{"id":"MAL-2025-17596","summary":"Malicious code in cors-proxy-server (npm)","details":"The package cors-proxy-server was found to contain malicious code.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n","modified":"2025-09-26T11:06:44Z","published":"2025-08-14T18:52:04Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2025-04490","import_time":"2025-08-29T06:42:18.029458698Z","modified_time":"2025-08-28T07:24:32Z","sha256":"1cc4b6bdb7ea8c723bf481217ebb822e09ac8f3bfe369914590891120ac0bc9a","source":"reversing-labs","versions":["1.0.1"]},{"sha256":"218b5abdf485cd915d3cb1ce71a0d8d22ba0ae8ec6b92dfe17454b7bad93a84d","source":"reversing-labs","versions":["1.0.5","1.0.4","1.0.2","1.0.6","1.0.0"],"id":"RLUA-2025-04977","import_time":"2025-09-26T11:06:11.572424417Z","modified_time":"2025-09-26T09:27:04Z"}]},"affected":[{"package":{"name":"cors-proxy-server","ecosystem":"npm","purl":"pkg:npm/cors-proxy-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["1.0.1","1.0.5","1.0.4","1.0.2","1.0.6","1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cors-proxy-server/MAL-2025-17596.json"}}],"schema_version":"1.7.3","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}