MAL-2025-6889

    Dashboard / Malicious Package / MAL-2025-6889

    MAL-2025-6889

    Published: 16 Aug 2025Last Modified: 17 Aug 2025

    Summary: Malicious code in aog-lib (npm)

    Details: Source: ossf-package-analysis (741266c7bad6d1e60680d0242b4f212454b09ca9647a683b5b314b262760943d) The OpenSSF Package Analysis project identified 'aog-lib' @ 2.2.4 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.

    References:

    Affected packages

    Package

    Name: aog-lib

    Purl: pkg:npm/aog-lib

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.2.4
    2.2.5
    MAL-2025-6889 | CVE-DB