Malicious Package in sdfjghlkfjdshlkjdhsfg
Critical severity
GitHub Reviewed
Published
Sep 3, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 3, 2020
Last updated
Jan 9, 2023
All versions of
sdfjghlkfjdshlkjdhsfg
contain malicious code. The package is essentially a worm that fetches all packages owned by the user, adds a script to self-replicate as a preinstall script and publishes a new version.Recommendation
Remove the package from your environment and ensure all packages owned were not impacted.
References