{"schema_version":"1.7.5","id":"MAL-2025-192453","published":"2025-12-11T01:47:51Z","modified":"2026-03-19T12:45:40.061742Z","summary":"Malicious code in libxmlfinal4 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d41a78ad1712a21fd085e3a8188b1e5522b8140cdc8b562d5ff933ceefe923f6)\nThe package libxmlfinal4 was found to contain malicious code.\n","affected":[{"package":{"name":"libxmlfinal4","ecosystem":"npm","purl":"pkg:npm/libxmlfinal4"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["0.30.3"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/libxmlfinal4/MAL-2025-192453.json"}}],"database_specific":{"malicious-packages-origins":[{"import_time":"2025-12-11T02:41:24.41235507Z","modified_time":"2025-12-11T01:47:51Z","ranges":[{"events":[{"introduced":"0"}],"type":"SEMVER"}],"sha256":"d41a78ad1712a21fd085e3a8188b1e5522b8140cdc8b562d5ff933ceefe923f6","source":"amazon-inspector"},{"id":"RLMA-2026-01404","import_time":"2026-03-19T12:18:58.947807381Z","modified_time":"2026-03-18T12:57:26Z","sha256":"4b3f06b8de1375e6ce974cad4a9906d6c308f47bae27ff7e5d653ca479bdf43e","source":"reversing-labs","versions":["0.30.3"]}]},"credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}