{"id":"MAL-2025-349","summary":"Malicious code in chkpkit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (2abd5e119e59d609551d6fcaf5128bad86491c26cc6b721014c324d54e930a7e)\nThe OpenSSF Package Analysis project identified 'chkpkit' @ 99.99.9-9.99 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2025-02-03T18:38:39Z","published":"2025-01-23T11:55:57Z","database_specific":{"malicious-packages-origins":[{"sha256":"453a5a38c1ddda1304d12d5c7b494eaca1b2e5463c0685141485938fb0858948","versions":["99.99.94"],"modified_time":"2025-01-23T12:15:54Z","import_time":"2025-01-23T12:45:58.451888271Z","source":"ossf-package-analysis"},{"sha256":"6a8be7f40bc28734ffc0196f3a098ced641af01dd4253dbbab0708289ebd5915","versions":["99.99.98"],"modified_time":"2025-01-23T12:20:35Z","import_time":"2025-01-23T12:45:58.559619841Z","source":"ossf-package-analysis"},{"sha256":"2abd5e119e59d609551d6fcaf5128bad86491c26cc6b721014c324d54e930a7e","versions":["99.99.9-9.99"],"modified_time":"2025-01-23T11:55:57Z","import_time":"2025-01-30T00:49:16.679669611Z","source":"ossf-package-analysis"},{"sha256":"e9cda78590b9a53e713b875e6cbe1fad937079b395ad98544db3bf7dd16f43fa","versions":["99.99.99"],"modified_time":"2025-02-03T16:49:01Z","import_time":"2025-02-03T18:37:48.142310442Z","id":"RLMA-2025-00105","source":"reversing-labs"}]},"affected":[{"package":{"name":"chkpkit","ecosystem":"npm","purl":"pkg:npm/chkpkit"},"versions":["99.99.94","99.99.98","99.99.9-9.99","99.99.99"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chkpkit/MAL-2025-349.json"}}],"schema_version":"1.7.3","credits":[{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}