{"id":"MAL-2025-192722","summary":"Malicious code in chai-as-deploy (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6777d6fb72a2a1e304855ebdd4aa8f8e5e8410136ebcc580b71b5e5f4152eaf2)\nThe package chai-as-deploy was found to contain malicious code.\n","aliases":["SNYK-JS-CHAIASDEPLOY-14152234"],"modified":"2026-03-19T12:40:55.248827Z","published":"2025-12-23T08:02:05Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2025-06082","import_time":"2025-12-23T16:08:08.460074645Z","modified_time":"2025-12-23T08:02:05Z","sha256":"c2a2377ff0458c7dab6c3eca4e14a88b729d15442e668869a56773dc24ccf50e","source":"reversing-labs","versions":["2.4.1"]},{"source":"amazon-inspector","versions":["2.4.1"],"import_time":"2025-12-24T00:51:44.328179675Z","modified_time":"2025-12-24T00:41:11Z","sha256":"6777d6fb72a2a1e304855ebdd4aa8f8e5e8410136ebcc580b71b5e5f4152eaf2"},{"import_time":"2026-03-19T12:20:50.899155015Z","modified_time":"2026-03-18T12:42:13Z","sha256":"e73d8f915293f1a7e37751ab5a000de0583bfc62a154b3769f6804f03975e0ce","source":"reversing-labs","id":"RLUA-2026-01145"}]},"references":[{"type":"ARTICLE","url":"https://socket.dev/blog/north-korea-contagious-interview-npm-attacks"},{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-JS-CHAIASDEPLOY-14152234"},{"type":"ARTICLE","url":"https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html"}],"affected":[{"package":{"name":"chai-as-deploy","ecosystem":"npm","purl":"pkg:npm/chai-as-deploy"},"versions":["2.4.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-deploy/MAL-2025-192722.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}