0.1.1
1 years ago
1 years ago
Known vulnerabilities in the @joyfill/layouts package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@joyfill/layouts is a malicious package. This package contains a supply chain compromise that executes a malicious payload immediately upon import of the vulnerable versions. When loaded, the package uses decentralized blockchain resolvers (Tron, Aptos, BNB Smart Chain) to fetch and execute an obfuscated Remote Access Trojan (RAT) and an infostealer. It establishes persistent remote control, spawns detached background processes to survive build termination, and steals browser data, crypto wallet extensions, VS Code storage, and Git/GitHub credentials. How to fix Malicious Package? Avoid using all malicious instances of the | =0.1.2-2773.beta.0=0.1.2-2773.beta.1=0.1.2-2773.beta.2 |