MAL-2025-4425

    Dashboard / Malicious Package / MAL-2025-4425

    MAL-2025-4425

    Published: 25 May 2025Last Modified: 29 May 2025Aliases: 
    GHSA-92fg-639p-gcpp

    Summary: Malicious code in blocks-nextjs (npm)

    Details: The package communicates with a domain associated with malicious activity. Source: ghsa-malware (1ae607db145f1ae39e7375c25cd19509f7f82eb76be82e74ff5cc37650ef27ba) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it. Source: ossf-package-analysis (47f100e21c0ffa4aadef7d45fef11d6ed8d3c73ec4fdfb9ebb6e58178d5279d7) The OpenSSF Package Analysis project identified 'blocks-nextjs' @ 9999.9999.10000 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: blocks-nextjs

    Purl: pkg:npm/blocks-nextjs

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    9999.9999.9999
    9999.9999.10000
    9999.9999.10002
    9999.9999.10004
    9999.9999.10005
    9999.9999.10006
    9999.9999.10009
    9999.9999.10008
    9999.9999.10011
    9999.9999.10007
    9999.9999.10012
    9999.9999.10010
    9999.9999.10015
    9999.9999.10016
    9999.9999.10020
    9999.9999.10023
    9999.9999.10029
    9999.9999.10026
    9999.9999.10027
    9999.9999.10032
    9999.9999.10030
    9999.9999.10025
    9999.9999.10034
    MAL-2025-4425 | CVE-DB