{"id":"MAL-2025-191600","summary":"Malicious code in vite-dynamic-chunks (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6babb911a34c3564bc3482994130fa36a5b088b1132550960a97582c74ed11f8)\nThe package vite-dynamic-chunks was found to contain malicious code.\n","aliases":["SNYK-JS-VITEDYNAMICCHUNKS-14152344"],"modified":"2026-03-19T12:48:58.868789Z","published":"2025-12-01T13:29:03Z","database_specific":{"malicious-packages-origins":[{"source":"reversing-labs","modified_time":"2025-12-01T13:29:03Z","import_time":"2025-12-02T09:09:56.255783343Z","id":"RLMA-2025-05983","sha256":"d4d475ae9d4e14cca59fc3b104a304e083bba0ff71cef84afd7a1d9882bbe6ef","versions":["2.0.6","2.0.7"]},{"source":"amazon-inspector","modified_time":"2025-12-02T21:11:00Z","import_time":"2025-12-02T21:35:54.33351746Z","sha256":"6babb911a34c3564bc3482994130fa36a5b088b1132550960a97582c74ed11f8","versions":["2.0.6","2.0.7"]},{"source":"reversing-labs","modified_time":"2025-12-23T08:35:03Z","import_time":"2025-12-24T10:07:36.035046729Z","id":"RLUA-2025-06527","sha256":"f82863743c878fc4f0783a57e2a32610a73fcf5788b9084d25e61f9f80397e1b"},{"source":"reversing-labs","modified_time":"2026-03-18T13:14:54Z","import_time":"2026-03-19T12:21:01.924560979Z","id":"RLUA-2026-01642","sha256":"b600b60f85f6b913b9d29ff20efca916b2600e3b7e6e9e277774c47019d23430"}]},"references":[{"type":"ARTICLE","url":"https://socket.dev/blog/north-korea-contagious-interview-npm-attacks"},{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-JS-VITEDYNAMICCHUNKS-14152344"},{"type":"ARTICLE","url":"https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html"}],"affected":[{"package":{"name":"vite-dynamic-chunks","ecosystem":"npm","purl":"pkg:npm/vite-dynamic-chunks"},"versions":["2.0.6","2.0.7"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/vite-dynamic-chunks/MAL-2025-191600.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}