Malicious Package Affecting dev-log-core package, versions *


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-DEVLOGCORE-15931516
  • published8 Apr 2026
  • disclosed6 Apr 2026
  • creditsocket.dev

Introduced: 6 Apr 2026

New Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the dev-log-core package.

Overview

dev-log-core is a malicious package. This package is the part of North Korea’s Contagious Interview Campaign and contains malicious payload, weaponised to steal credentials, wallets, and enable remote access to affected systems. The package attempts to mimic a legitimate package and the malicious payload is delivered upon calling functions that look normal for the package’s claimed purpose.

References

CVSS Base Scores

version 4.0
version 3.1