executable-stories-playwright@8.4.3

BDD-style executable stories for Playwright Test with documentation generation

Direct Vulnerabilities

Known vulnerabilities in the executable-stories-playwright package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Embedded Malicious Code

Affected versions of this package are vulnerable to Embedded Malicious Code containing a malicious binding.gyp file that drops and runs a self-propagating cloud secret stealer. The malicious code attempts to exfiltrate AWS, GCP, Azure, Vault, and Kubernetes credentials, as well as npm and RubyGems registry tokens, and GitHub Actions OIDC tokens.

The added package/index.js, containing the obfuscated payload, is called silently during npm install execution, without the use of postinstall scripts. This file is deliberately confused with the legitimate entry point dist/index.js, but is not itself an entrypoint.

How to fix Embedded Malicious Code?

Avoid using all malicious instances of the executable-stories-playwright package.

=3.1.1=4.0.1=5.0.1=6.1.1=7.0.3=8.4.3