MAL-2025-192811
Dashboard / Malicious Package / MAL-2025-192811
MAL-2025-192811
Summary: Malicious code in jsonauto (npm)
Details: Source: amazon-inspector (ce9bf596900bc5133273dd4e77700e5636518a55c780b186e42a26d30efeabc3) The package jsonauto was found to contain malicious code.
References: https://socket.dev/blog/north-korea-contagious-interview-npm-attacks, https://security.snyk.io/vuln/SNYK-JS-JSONAUTO-14152267, https://thehackernews.com/2025/11/north-korean-hackers-deploy-197-npm.html
Affected packages
Package
Name: jsonauto
Purl: pkg:npm/jsonauto
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
5.1.0
