VYPR

npm · Malicious package advisory

Malware

auth-handler

MAL-2025-192712

Malicious code in auth-handler (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (79d1be042f1565157d9c5e97b927919aa32bedb254b501aa374caf00c242ee83)
The package auth-handler was found to contain malicious code.

Compromised versions (1)

  • 2.5.8

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.