{"id":"MAL-2025-192712","summary":"Malicious code in auth-handler (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (79d1be042f1565157d9c5e97b927919aa32bedb254b501aa374caf00c242ee83)\nThe package auth-handler was found to contain malicious code.\n","aliases":["SNYK-JS-AUTHHANDLER-14152228"],"modified":"2026-03-19T12:40:07.902568Z","published":"2025-12-23T07:59:48Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2025-06063","import_time":"2025-12-23T15:39:08.992855099Z","modified_time":"2025-12-23T07:59:48Z","sha256":"7b1ef6a437d15ff984467bae6811469d0451b0b00fe3b9f2b7a43da5a15e6556","source":"reversing-labs","versions":["2.5.8"]},{"sha256":"79d1be042f1565157d9c5e97b927919aa32bedb254b501aa374caf00c242ee83","source":"amazon-inspector","versions":["2.5.8"],"import_time":"2025-12-24T00:51:44.267384505Z","modified_time":"2025-12-24T00:41:11Z"},{"import_time":"2026-03-19T12:20:49.735336004Z","modified_time":"2026-03-18T12:39:39Z","sha256":"c7d7c686621c8937d5938b503be6a128aae85c1644121878ec5e5b30fb98c03e","source":"reversing-labs","id":"RLUA-2026-01112"}]},"references":[{"type":"ARTICLE","url":"https://socket.dev/blog/north-korea-contagious-interview-npm-attacks"},{"type":"ARTICLE","url":"https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html"},{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-JS-AUTHHANDLER-14152228"}],"affected":[{"package":{"name":"auth-handler","ecosystem":"npm","purl":"pkg:npm/auth-handler"},"versions":["2.5.8"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/auth-handler/MAL-2025-192712.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}