{"id":"MAL-2025-6902","summary":"Malicious code in @goes-funky/y42-vscode (npm)","details":"The package communicates with a domain associated with malicious activity.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (f2e0a98abbd9d80612a2ceffc06aac69b23dd12331094d9588992d8789631cf4)\nThe OpenSSF Package Analysis project identified '@goes-funky/y42-vscode' @ 99.99.103 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2025-08-29T06:43:15Z","published":"2025-08-14T19:23:44Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2025-08-17T15:15:37Z","sha256":"f2e0a98abbd9d80612a2ceffc06aac69b23dd12331094d9588992d8789631cf4","source":"ossf-package-analysis","versions":["99.99.103"],"import_time":"2025-08-18T06:09:46.983922388Z"},{"sha256":"c7aeb1b5b43f11b4e6cb967078ed13aa4f9b991be0c208668092b61487ae5ab0","source":"reversing-labs","versions":["9.9.9","99.99.99","99.99.100","99.99.101","99.99.103"],"id":"RLMA-2025-04315","import_time":"2025-08-29T06:41:59.774557891Z","modified_time":"2025-08-28T07:13:44Z"}]},"affected":[{"package":{"name":"@goes-funky/y42-vscode","ecosystem":"npm","purl":"pkg:npm/%40goes-funky/y42-vscode"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.9.9"}]}],"versions":["99.99.103","9.9.9","99.99.99","99.99.100","99.99.101"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@goes-funky/y42-vscode/MAL-2025-6902.json"}}],"schema_version":"1.7.3","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}