MAL-2025-192377

    Dashboard / Malicious Package / MAL-2025-192377

    MAL-2025-192377

    Published: 8 Dec 2025Last Modified: 11 Dec 2025

    Summary: Malicious code in gs-uitk-lodash (npm)

    Details: Source: amazon-inspector (2de2e606bc9fde8de540caf63cbded837e1bbbd7bc6bd2d477e38dcf89a76f0b) The package gs-uitk-lodash was found to contain malicious code. Source: ossf-package-analysis (c89a6d85d1019b9d98f88e94d18fd4ec4ae045bd6f941941e9bdde517a749fdd) The OpenSSF Package Analysis project identified 'gs-uitk-lodash' @ 35.3.3 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.

    References:

    Affected packages

    Package

    Name: gs-uitk-lodash

    Purl: pkg:npm/gs-uitk-lodash

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    35.3.3