{"id":"MAL-2025-192727","summary":"Malicious code in cookie-breaker (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b64a69ed1f4bd909ec9439986055d180490e4928aba8d08b45b4645956f63b14)\nThe package cookie-breaker was found to contain malicious code.\n","aliases":["SNYK-JS-COOKIEBREAKER-14152248"],"modified":"2026-03-19T12:42:47.786019Z","published":"2025-12-23T08:03:18Z","database_specific":{"malicious-packages-origins":[{"import_time":"2025-12-23T16:08:09.441701021Z","modified_time":"2025-12-23T08:03:18Z","sha256":"0a13a13f5d53e7ca5aa83648bc2e29bff5f109099069a902e61eb975c3f0a017","source":"reversing-labs","versions":["1.1.0"],"id":"RLMA-2025-06100"},{"import_time":"2025-12-24T00:51:37.80134868Z","modified_time":"2025-12-24T00:41:11Z","sha256":"b64a69ed1f4bd909ec9439986055d180490e4928aba8d08b45b4645956f63b14","source":"amazon-inspector","versions":["1.1.0"]},{"id":"RLUA-2026-01221","import_time":"2026-03-19T12:20:52.262950382Z","modified_time":"2026-03-18T12:44:55Z","sha256":"4f6fdd5ed81eb56678538e9740eb8ecbb7422bf12b2f8267a35d8ef5fb0887ae","source":"reversing-labs"}]},"references":[{"type":"ARTICLE","url":"https://socket.dev/blog/north-korea-contagious-interview-npm-attacks"},{"type":"ARTICLE","url":"https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html"},{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-JS-COOKIEBREAKER-14152248"}],"affected":[{"package":{"name":"cookie-breaker","ecosystem":"npm","purl":"pkg:npm/cookie-breaker"},"versions":["1.1.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cookie-breaker/MAL-2025-192727.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}