{"id":"MAL-2025-27562","summary":"Malicious code in nit-quotation-service-core-lib (npm)","details":"The package nit-quotation-service-core-lib was found to contain malicious code.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n","modified":"2025-09-26T11:06:45Z","published":"2025-08-14T18:52:04Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2025-04609","import_time":"2025-08-29T06:42:28.956061578Z","modified_time":"2025-08-28T07:34:31Z","sha256":"5ac49036b20bd95b27db121bedb9d082525a627ba4f49915d93bd128976efa65","source":"reversing-labs","versions":["1.0.1-SNAPSHOT.32","1.0.1-SNAPSHOT.33","1.0.1-SNAPSHOT.34","1.0.1-SNAPSHOT.35","1.0.1-SNAPSHOT.36","1.0.1-SNAPSHOT.37","1.0.1-SNAPSHOT.38","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8"]},{"import_time":"2025-09-26T11:06:12.583475956Z","modified_time":"2025-09-26T09:37:31Z","sha256":"7ed2576f3d2c1f53cd5dcad4a35fca4bc4336fb4f144709177186bca07ab885f","source":"reversing-labs","versions":["1.0.2","1.0.3"],"id":"RLUA-2025-05085"}]},"affected":[{"package":{"name":"nit-quotation-service-core-lib","ecosystem":"npm","purl":"pkg:npm/nit-quotation-service-core-lib"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["1.0.1-SNAPSHOT.32","1.0.1-SNAPSHOT.33","1.0.1-SNAPSHOT.34","1.0.1-SNAPSHOT.35","1.0.1-SNAPSHOT.36","1.0.1-SNAPSHOT.37","1.0.1-SNAPSHOT.38","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.2","1.0.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/nit-quotation-service-core-lib/MAL-2025-27562.json"}}],"schema_version":"1.7.3","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}