{"id":"MAL-2025-49276","summary":"Malicious code in vue2-script-ext-html-webpack-plugin (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (747331ee9a0695a63f863ebc84ad9508b515a9c8dfe77477314ff8de5a5aba40)\nThe package vue2-script-ext-html-webpack-plugin was found to contain malicious code.\n","modified":"2025-10-31T01:28:08Z","published":"2025-10-31T01:28:08Z","database_specific":{"malicious-packages-origins":[{"import_time":"2025-10-31T01:34:32.791072261Z","modified_time":"2025-10-31T01:28:08Z","ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"sha256":"747331ee9a0695a63f863ebc84ad9508b515a9c8dfe77477314ff8de5a5aba40","source":"amazon-inspector"}]},"affected":[{"package":{"name":"vue2-script-ext-html-webpack-plugin","ecosystem":"npm","purl":"pkg:npm/vue2-script-ext-html-webpack-plugin"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/vue2-script-ext-html-webpack-plugin/MAL-2025-49276.json"}}],"schema_version":"1.7.3","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}