{"id":"MAL-2025-192855","summary":"Malicious code in react-flex-tools (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1ab5b4a0a39a8b9ccc5dd27ea7207f3006128207203ee8ceb99dbef4be0ec9d3)\nThe package react-flex-tools was found to contain malicious code.\n","aliases":["SNYK-JS-REACTFLEXTOOLS-14152285"],"modified":"2026-03-19T12:47:38.559478Z","published":"2025-12-23T08:26:31Z","database_specific":{"malicious-packages-origins":[{"sha256":"2e340363a8999fa89f8f3ad5ea5318c4d32edd746aa2d80f4f89da2b1b69fd94","source":"reversing-labs","versions":["2.0.1"],"id":"RLMA-2025-06457","import_time":"2025-12-24T10:07:26.824831642Z","modified_time":"2025-12-23T08:26:31Z"},{"import_time":"2026-01-02T21:35:53.094030078Z","modified_time":"2026-01-02T21:29:26Z","sha256":"1ab5b4a0a39a8b9ccc5dd27ea7207f3006128207203ee8ceb99dbef4be0ec9d3","source":"amazon-inspector","versions":["2.0.1"]},{"id":"RLUA-2026-01527","import_time":"2026-03-19T12:20:57.64902498Z","modified_time":"2026-03-18T13:06:11Z","sha256":"bc0a8579ece68eb524c896cf4694565f937a05bdb5a8c9a9927dc526accbc625","source":"reversing-labs"}]},"references":[{"type":"ARTICLE","url":"https://socket.dev/blog/north-korea-contagious-interview-npm-attacks"},{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-JS-REACTFLEXTOOLS-14152285"},{"type":"ARTICLE","url":"https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html"}],"affected":[{"package":{"name":"react-flex-tools","ecosystem":"npm","purl":"pkg:npm/react-flex-tools"},"versions":["2.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/react-flex-tools/MAL-2025-192855.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}