{"id":"MAL-2025-42049","summary":"Malicious code in oclif-dev (npm)","details":"The package oclif-dev was found to contain malicious code.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: google-open-source-security (9cf078178f5da45231528dbb9bb1883266f18b9c8cd4784a7c8542a3c3d4de7b)\nThis package installs a dependency hosted on a custom domain that runs an\ninfo stealer during installation. The info stealer focuses on stealing\nnpm, git, and other CI/CD related tokens.\n","modified":"2025-12-02T10:11:01.064431Z","published":"2025-08-29T18:55:03Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2025-05100","import_time":"2025-09-26T11:05:59.889374093Z","modified_time":"2025-09-26T09:38:16Z","sha256":"10cfeb2505ac779f44f00756dd80ffbab895892b867d7a5d23748259c01832f8","source":"reversing-labs","versions":["99.0.0"]},{"import_time":"2025-10-30T03:28:38.884247Z","modified_time":"2025-10-30T03:28:23Z","sha256":"9cf078178f5da45231528dbb9bb1883266f18b9c8cd4784a7c8542a3c3d4de7b","source":"google-open-source-security","versions":["99.0.0"]},{"modified_time":"2025-12-01T13:19:35Z","sha256":"a2e897b4dcc2503c353e7c0b2ef1df695b3b86a4b03841a9005620b6ba2e776a","source":"reversing-labs","id":"RLUA-2025-05899","import_time":"2025-12-02T09:10:09.518948481Z"}]},"references":[{"type":"WEB","url":"https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies"},{"type":"WEB","url":"https://www.sonatype.com/blog/phantomraven-npm-malware"}],"affected":[{"package":{"name":"oclif-dev","ecosystem":"npm","purl":"pkg:npm/oclif-dev"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["99.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/oclif-dev/MAL-2025-42049.json"}}],"schema_version":"1.7.3","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}