strapi-plugin-content-sync@0.0.1-security

security holding package

Direct Vulnerabilities

Known vulnerabilities in the strapi-plugin-content-sync package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Malicious Package

strapi-plugin-content-sync is a malicious package. This package contains malicious code that conceals a command-and-control agent and credential harvester. A malicious actor published a coordinated campaign of thirty-six packages disguised as community Strapi CMS plugins. These packages aren't affiliated with the official Strapi project, which is scoped under @strapi/. Using unscoped names is a social engineering tactic, and the packages serve no legitimate purpose.

How to fix Malicious Package?

Avoid using all malicious instances of the strapi-plugin-content-sync package.

*