@joyfill/layouts@0.1.2-2773.beta.1

Handles page and field layouts for Joyfill JS SDK

  • latest version

    0.1.1

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @joyfill/layouts package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Malicious Package

    @joyfill/layouts is a malicious package. This package contains a supply chain compromise that executes a malicious payload immediately upon import of the vulnerable versions. When loaded, the package uses decentralized blockchain resolvers (Tron, Aptos, BNB Smart Chain) to fetch and execute an obfuscated Remote Access Trojan (RAT) and an infostealer. It establishes persistent remote control, spawns detached background processes to survive build termination, and steals browser data, crypto wallet extensions, VS Code storage, and Git/GitHub credentials.

    How to fix Malicious Package?

    Avoid using all malicious instances of the @joyfill/layouts package.

    =0.1.2-2773.beta.0=0.1.2-2773.beta.1=0.1.2-2773.beta.2