flatmap-stream@0.0.1-security vulnerabilities

security holding package

Direct Vulnerabilities

Known vulnerabilities in the flatmap-stream package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • C
Malicious Package

flatmap-stream is a malicious package which was used in order to steal bitcoins from wallets. The malicious code was able to check if the copay-dash package was installed, and then attempt to steal the bitcoins stored in it. It was distributed by hijacking the popular event-stream package and adding flatmap-stream as a dependency.

You can read more about the malicious code on our blog.

How to fix Malicious Package?

Avoid using any version of flatmap-stream and version 3.3.6 of event-stream.

*