MAL-2025-191572
Dashboard / Malicious Package / MAL-2025-191572
MAL-2025-191572
Summary: Malicious code in cwanner (npm)
Details: Source: amazon-inspector (b802af5dc124ecff02d4bd0f8cb34612fa149151e1dea636d8235762f0e8c7ce) The package cwanner was found to contain malicious code.
References: https://socket.dev/blog/north-korea-contagious-interview-npm-attacks, https://security.snyk.io/vuln/SNYK-JS-CWANNER-14152252, https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html
Affected packages
Package
Name: cwanner
Purl: pkg:npm/cwanner
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
9.2.0
