{"schema_version":"1.7.3","id":"MAL-2025-191563","published":"2025-12-01T12:58:38Z","modified":"2025-12-02T21:58:42.132798Z","summary":"Malicious code in @ukg-oneapp/common-lib (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b059e51ff63f10ad83b16a1eeebedec98eaba6ac470197fe119a0e5e404af75d)\nThe package @ukg-oneapp/common-lib was found to contain malicious code.\n","affected":[{"package":{"name":"@ukg-oneapp/common-lib","ecosystem":"npm","purl":"pkg:npm/%40ukg-oneapp/common-lib"},"versions":["99.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@ukg-oneapp/common-lib/MAL-2025-191563.json"}}],"database_specific":{"malicious-packages-origins":[{"id":"RLMA-2025-05669","import_time":"2025-12-02T09:09:40.914920728Z","modified_time":"2025-12-01T12:58:38Z","sha256":"4f1a2dd275bb4ae1dc30c7c16141033fabe4e11f889aa18b6449815c65a6931a","source":"reversing-labs","versions":["99.0.0"]},{"import_time":"2025-12-02T21:35:53.220051001Z","modified_time":"2025-12-02T21:11:00Z","sha256":"b059e51ff63f10ad83b16a1eeebedec98eaba6ac470197fe119a0e5e404af75d","source":"amazon-inspector","versions":["99.0.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}