0.0.1-security
3 years ago
3 years ago
Known vulnerabilities in the lodash.isstgrng package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for freeVulnerability | Vulnerable Version |
---|---|
lodash.isstgrng is a malicious package. This package contains a malicious code that infects Linux hosts with cryptominers by downloading a malicious Bash script from the attacker server via a Bitly URL. How to fix Malicious Package? Avoid using all malicious instances of the | * |