{"id":"MAL-2025-48726","summary":"Malicious code in ldhpgemrdhs92007 (npm)","details":"The package ldhpgemrdhs92007 was found to contain malicious code.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n","modified":"2025-12-02T10:10:32.343972Z","published":"2025-10-26T19:03:27Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2025-05855","import_time":"2025-12-02T09:09:51.382835213Z","versions":["1.250701.10915","1.250701.10925","1.250701.10929","1.250701.10936","1.250701.10939","1.250701.11042","1.250701.11128","1.250701.11259","1.250709.11534","1.250709.11619","1.250709.11626","1.250710.10907","1.250710.10938","1.250712.11516","1.250712.11555","1.250713.11250","1.250713.11253","1.250713.11401","1.250714.10940","1.250724.10950","1.250724.11109","1.250724.11113","1.250725.12014","1.250726.10029","1.250726.10814","1.250726.11020","1.250726.11709","1.250726.11744","1.250727.11906","1.250728.12156","1.250729.11526","1.250730.11136","1.250730.11141","1.250730.11146","1.250730.11437","1.250730.11642","1.250730.12029","1.250731.10755","1.250731.11345","1.250801.11333","1.250801.11451","1.250801.11550","1.250801.11554","1.250801.11559","1.250801.11731","1.250801.12028","1.250805.11142","1.250805.11402","1.250805.11850","1.250805.12016","1.250806.10824","1.250806.10943","1.250806.10947","1.250806.11410","1.250806.11422","1.250806.11446","1.250806.11548","1.250807.11035","1.250808.11108","1.250808.11426","1.250808.11441","1.250808.11508","1.250808.12106","1.250809.11028","1.250809.11715","1.250810.11939","1.250810.12016","1.250811.12053","1.250811.12106","1.250812.11105","1.250812.11111","1.250814.11124","1.250814.11148","1.250814.11833","1.250814.11913","1.250817.11653","1.250819.11906","1.250820.10848","1.250820.10851","1.250820.10911","1.250820.10921","1.250820.10926","1.250820.10929","1.250820.11314","1.250820.11323","1.250820.11333","1.250820.11353","1.250820.11404","1.250820.11407","1.250820.11412","1.250820.11442","1.250820.11453","1.250820.11507","1.250820.11533","1.250820.11958","1.250821.11345","1.250821.11923","1.250822.10944","1.250822.11140","1.250829.11407","1.250905.11102","1.250905.11104","1.250905.11107","1.250905.11111","1.250905.11113","1.250908.11434","1.250908.11504","1.250908.11549","1.250908.12051","1.250909.11353","1.250910.10934","1.250910.11140","1.250910.11449","1.250910.11515","1.250910.11930","1.250910.11954","1.250911.10805","1.250911.10916","1.250911.10921","1.250911.10927","1.250911.11346","1.250911.11555","1.250911.11834","1.250911.11839","1.250911.11846","1.250912.10938","1.250912.11847","1.250913.11524","1.250914.11809","1.250915.10848","1.250915.11514","1.250915.11829","1.250916.10755","1.250916.11428","1.250917.10759","1.250917.11418","1.250918.10825","1.250918.11133","1.250918.11157","1.250918.11312","1.250918.11322","1.250918.11328","1.250918.11341","1.250918.11543","1.250918.11549","1.250918.11552","1.250918.11554","1.250918.11813","1.250918.11821","1.250919.11154","1.250922.11316","1.250922.11537","1.250922.11542","1.250922.11600","1.250923.10832","1.250923.11037","1.250925.11314","1.250925.11345","1.250926.10948","1.250926.11140","1.250926.11418","1.250926.11523","1.250928.11527","1.251001.11441","1.251002.11123","1.251002.11521","1.251003.10934","1.251003.10935","1.251003.11455","1.251003.11815","1.251006.11513","1.251007.11520","1.251008.11825","1.251009.11011","1.251009.11511","1.251015.10824","1.251015.10911","1.251015.10932","1.251015.10949","1.251015.11047","1.251015.11105","1.251016.11323","1.251018.11030","1.251020.10847","1.251021.10754","1.251021.11510","1.251021.11519","1.251022.11335","1.251022.11437","1.251022.11440","1.251022.11443"],"source":"reversing-labs","modified_time":"2025-12-01T13:15:55Z","sha256":"1afd1548f76f117fbad98e076a95def945df9bd2e899a3c5e293c9c3c1f2c949"}]},"references":[{"type":"WEB","url":"https://www.getsafety.com/blog-posts/javascript-rat-targets-banks"}],"affected":[{"package":{"name":"ldhpgemrdhs92007","ecosystem":"npm","purl":"pkg:npm/ldhpgemrdhs92007"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["1.250701.10915","1.250701.10925","1.250701.10929","1.250701.10936","1.250701.10939","1.250701.11042","1.250701.11128","1.250701.11259","1.250709.11534","1.250709.11619","1.250709.11626","1.250710.10907","1.250710.10938","1.250712.11516","1.250712.11555","1.250713.11250","1.250713.11253","1.250713.11401","1.250714.10940","1.250724.10950","1.250724.11109","1.250724.11113","1.250725.12014","1.250726.10029","1.250726.10814","1.250726.11020","1.250726.11709","1.250726.11744","1.250727.11906","1.250728.12156","1.250729.11526","1.250730.11136","1.250730.11141","1.250730.11146","1.250730.11437","1.250730.11642","1.250730.12029","1.250731.10755","1.250731.11345","1.250801.11333","1.250801.11451","1.250801.11550","1.250801.11554","1.250801.11559","1.250801.11731","1.250801.12028","1.250805.11142","1.250805.11402","1.250805.11850","1.250805.12016","1.250806.10824","1.250806.10943","1.250806.10947","1.250806.11410","1.250806.11422","1.250806.11446","1.250806.11548","1.250807.11035","1.250808.11108","1.250808.11426","1.250808.11441","1.250808.11508","1.250808.12106","1.250809.11028","1.250809.11715","1.250810.11939","1.250810.12016","1.250811.12053","1.250811.12106","1.250812.11105","1.250812.11111","1.250814.11124","1.250814.11148","1.250814.11833","1.250814.11913","1.250817.11653","1.250819.11906","1.250820.10848","1.250820.10851","1.250820.10911","1.250820.10921","1.250820.10926","1.250820.10929","1.250820.11314","1.250820.11323","1.250820.11333","1.250820.11353","1.250820.11404","1.250820.11407","1.250820.11412","1.250820.11442","1.250820.11453","1.250820.11507","1.250820.11533","1.250820.11958","1.250821.11345","1.250821.11923","1.250822.10944","1.250822.11140","1.250829.11407","1.250905.11102","1.250905.11104","1.250905.11107","1.250905.11111","1.250905.11113","1.250908.11434","1.250908.11504","1.250908.11549","1.250908.12051","1.250909.11353","1.250910.10934","1.250910.11140","1.250910.11449","1.250910.11515","1.250910.11930","1.250910.11954","1.250911.10805","1.250911.10916","1.250911.10921","1.250911.10927","1.250911.11346","1.250911.11555","1.250911.11834","1.250911.11839","1.250911.11846","1.250912.10938","1.250912.11847","1.250913.11524","1.250914.11809","1.250915.10848","1.250915.11514","1.250915.11829","1.250916.10755","1.250916.11428","1.250917.10759","1.250917.11418","1.250918.10825","1.250918.11133","1.250918.11157","1.250918.11312","1.250918.11322","1.250918.11328","1.250918.11341","1.250918.11543","1.250918.11549","1.250918.11552","1.250918.11554","1.250918.11813","1.250918.11821","1.250919.11154","1.250922.11316","1.250922.11537","1.250922.11542","1.250922.11600","1.250923.10832","1.250923.11037","1.250925.11314","1.250925.11345","1.250926.10948","1.250926.11140","1.250926.11418","1.250926.11523","1.250928.11527","1.251001.11441","1.251002.11123","1.251002.11521","1.251003.10934","1.251003.10935","1.251003.11455","1.251003.11815","1.251006.11513","1.251007.11520","1.251008.11825","1.251009.11011","1.251009.11511","1.251015.10824","1.251015.10911","1.251015.10932","1.251015.10949","1.251015.11047","1.251015.11105","1.251016.11323","1.251018.11030","1.251020.10847","1.251021.10754","1.251021.11510","1.251021.11519","1.251022.11335","1.251022.11437","1.251022.11440","1.251022.11443"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ldhpgemrdhs92007/MAL-2025-48726.json"}}],"schema_version":"1.7.3","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}