{"id":"MAL-2025-192814","summary":"Malicious code in jsswapper (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d7808f95622190dd5e4eadbaa97bd926083dc09c84afae6f6ced7c4c978763d6)\nThe package jsswapper was found to contain malicious code.\n","aliases":["SNYK-JS-JSSWAPPER-14152272"],"modified":"2026-03-19T12:45:24.484195Z","published":"2025-12-23T08:18:14Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2025-12-23T08:18:14Z","sha256":"e04a3a6b43822bf43ab8230c5ff270747c4c790631a969111bbb63cff09b30da","source":"reversing-labs","versions":["7.2.7"],"id":"RLMA-2025-06380","import_time":"2025-12-24T10:07:24.054771361Z"},{"import_time":"2026-01-02T21:35:52.861433578Z","modified_time":"2026-01-02T21:29:26Z","sha256":"d7808f95622190dd5e4eadbaa97bd926083dc09c84afae6f6ced7c4c978763d6","source":"amazon-inspector","versions":["7.2.7"]},{"import_time":"2026-03-19T12:20:55.607945848Z","modified_time":"2026-03-18T12:56:24Z","sha256":"fe6a3b289dd802663d86b9c34fd541e82ef7fe22fb859e666534c6969aefc1d3","source":"reversing-labs","id":"RLUA-2026-01381"}]},"references":[{"type":"ARTICLE","url":"https://socket.dev/blog/north-korea-contagious-interview-npm-attacks"},{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-JS-JSSWAPPER-14152272"},{"type":"ARTICLE","url":"https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html"}],"affected":[{"package":{"name":"jsswapper","ecosystem":"npm","purl":"pkg:npm/jsswapper"},"versions":["7.2.7"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/jsswapper/MAL-2025-192814.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}