http-proxy-middelware@0.0.1-security vulnerabilities

security holding package

Direct Vulnerabilities

Known vulnerabilities in the http-proxy-middelware package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • H
Malicious Package

http-proxy-middelware is a malicious package. All versions of http-proxy-middelware contain malicious code. The index.js file attempts to download a file from a remote server and execute it. The file is not run upon installation - the package needs to be required or the index.js run manually. The package contains a typo in its code which lead to it not functioning properly. Additionally, the remote file it attempted to download is currently not retrievable anymore but might have been in the past and its contents are unknown.

How to fix Malicious Package?

Avoid using all malicious instances of the http-proxy-middelware package.

*