MAL-2025-49455

    Dashboard / Malicious Package / MAL-2025-49455

    MAL-2025-49455

    Published: 9 Nov 2025Last Modified: 9 Nov 2025

    Summary: Malicious code in startupkit-umbraco-webpack (npm)

    Details: Source: amazon-inspector (ee52f18349f18de229409043c934e6b5e843d702d63be72f2058f495d5cc7355) The package startupkit-umbraco-webpack was found to contain malicious code. Source: ossf-package-analysis (6eaa31bd3eb89c56888d49f6353e6dbc823343124d89a77e7023b56c98cea20a) The OpenSSF Package Analysis project identified 'startupkit-umbraco-webpack' @ 2.0.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    References:

    Affected packages

    Package

    Name: startupkit-umbraco-webpack

    Purl: pkg:npm/startupkit-umbraco-webpack

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    2.0.0
    MAL-2025-49455 | CVE-DB