MAL-2025-192377
Dashboard / Malicious Package / MAL-2025-192377
MAL-2025-192377
Published: 8 Dec 2025Last Modified: 11 Dec 2025
Summary: Malicious code in gs-uitk-lodash (npm)
Details: Source: amazon-inspector (2de2e606bc9fde8de540caf63cbded837e1bbbd7bc6bd2d477e38dcf89a76f0b) The package gs-uitk-lodash was found to contain malicious code. Source: ossf-package-analysis (c89a6d85d1019b9d98f88e94d18fd4ec4ae045bd6f941941e9bdde517a749fdd) The OpenSSF Package Analysis project identified 'gs-uitk-lodash' @ 35.3.3 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.
References:
Affected packages
Package
Name: gs-uitk-lodash
Purl: pkg:npm/gs-uitk-lodash
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
35.3.3
