
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Malicious Package
void-ulid is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.
Embedded Malicious Code
Affected versions of this package are vulnerable to Embedded Malicious Code. This package contains malicious code associated with the Shai-Hulud / Miasma software supply chain campaign, a large scale operation that has affected numerous packages across open source ecosystems. The malicious releases were published through a compromised maintainer account of a legitimate project as part of a broader credential theft campaign. The malicious functionality was not part of the original software and does not reflect the intent of the project's maintainers.
The malicious release abuses Python startup hooks (.pth files) to execute code automatically when Python starts, download additional payloads, and attempt to collect developer, cloud, CI/CD, and other sensitive credentials from affected systems. The main malicious payload is contained in _index.js, which runs on the javascript Bun runtime. The campaign targets a wide range of secrets, including source-control tokens, package publishing credentials, cloud access keys, SSH keys, and local configuration files.
Note:
Malicious versions may still be available on PyPI at the time of analysis; users should verify installed versions, remove affected releases where possible, and rotate any potentially exposed credentials.
Incorrect Check of Function Return Value
Affected versions of this package are vulnerable to Incorrect Check of Function Return Value in the "second factor" flow where FinishAssertionSteps fails to cross-check the verified credential handle against the requested username when a userHandle is not found for that username during the initial lookup. An attacker can gain unauthorized access by exploiting this flaw to impersonate another user.
Recent vulnerabilities disclosed by Snyk
- H
Command Injection in degit (npm)- C
Malicious Package in moustick (npm)- C
Malicious Package in cookie-parser-legacy (npm)- M
Arbitrary File Write via Archive Extraction (Zip Slip) in decompress (npm)- H
CSV Injection in json-2-csv (npm)
Snyk security
researchers
have disclosed
3497
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




