{"id":"MAL-2025-4047","summary":"Malicious code in wallet1-options (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (152e4326d8826107e6c4706758de644f8ac9a9785cd68f6f655461fd59016682)\nThe OpenSSF Package Analysis project identified 'wallet1-options' @ 100.0.4 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2025-05-19T18:00:53Z","published":"2025-05-19T18:00:53Z","database_specific":{"malicious-packages-origins":[{"versions":["100.0.4"],"import_time":"2025-05-20T01:34:18.416523031Z","modified_time":"2025-05-19T18:00:53Z","sha256":"152e4326d8826107e6c4706758de644f8ac9a9785cd68f6f655461fd59016682","source":"ossf-package-analysis"}]},"affected":[{"package":{"name":"wallet1-options","ecosystem":"npm","purl":"pkg:npm/wallet1-options"},"versions":["100.0.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wallet1-options/MAL-2025-4047.json"}}],"schema_version":"1.7.3","credits":[{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}