Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
sonatype-2025-004312
sonatype-2025-004312
Malicious Packages - Tue Oct 28 2025 [Dropper] [Lazarus]
Published Oct 28, 2025
https://help.sonatype.com/en/sonatype-malware-data.html
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-191600.json
CVSS Score
High
8.7
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
@mts-ds/icons
0.0.1-security
npm
@mts-ds/icons
2.4.0
npm
@mts-feedback/widget
0.4.9
npm
@mts-feedback/widget
0.5.0
npm
@mts-feedback/widget
0.5.1
npm
bootstrap-flexgrid
1.9.15
npm
bootstrap-setcolor
1.9.15
npm
bootstrap-setcolor
1.9.16
npm
bootstrap-setcolors
1.9.16
npm
bootstrap-setflexcolor
1.9.15
npm
dev-filterjs
1.0.2
npm
dev-filterjs
1.0.3
npm
dev-filterjs
1.0.4
npm
dev-filterjs
1.0.5
npm
dragon0905-vite-tsconfig-assistant
1.0.3
npm
glowmotion
1.9.7
npm
gridmancer
2.7.4
npm
hardhat-deploy-notifier
1.0.0
npm
js-log-print
1.0.0
npm
js-logger-beta
1.0.3
npm
muleforge
2.9.1
npm
next-plugin-uni-i18n
1.0.2
npm
next-plugin-uni-i18n
1.0.3
npm
next-plugin-uni-i18n
1.0.4
npm
next-plugin-uni-i18n
1.0.5
npm
pgforce
2.9.3
npm
pixel-bloom
10.29.11
npm
pixel-bloom
10.29.1
npm
pixel-bloom
10.29.4
npm
pixelblm
10.29.5
npm
postcss-preloader
0.0.1
npm
pretty-format-setting
1.0.3
npm
pretty-text-formatter
1.0.1
npm
reactjs-fabric
0.0.1-security
npm
reactjs-fabric
6.0.11
npm
reactjs-fabric
6.0.12
npm
shadeforge
2.7.4
npm
shadeforge
2.7.5
npm
style-config-tailwind
0.1.3
npm
style-tailwind-variant
1.0.4
npm
stylelint-configs-tailwindcss
1.3.4
npm
tailwind-areachart
2.8.8
npm
tailwind-barchart
2.8.6
npm
tailwind-canvas
2.9.5
npm
tailwind-cascade
2.1.5
npm
tailwind-chaos
1.7.4
npm
tailwind-chart
0.6.1
npm
tailwind-dynamic
2.5.2
npm
tailwind-elevate
1.4.7
npm
tailwind-fa-bridge
1.17.19
1-50 of 182
sonatype-2025-004312 | Components Impacted | Sonatype Guide | Sonatype Guide