0.0.1-security
8 days ago
8 days ago
Known vulnerabilities in the vite-plugin-next-refresh package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
vite-plugin-next-refresh is a malicious package. This is a "typosquatting" package, which means the package name is based on existing repositories, namespaces, or components, it aims to trick users to download the package which contains a malicious code. This package contains a hex-encoded loader which upon installation collects host metadata, decodes its follow-on script and fetches second-stage malware. How to fix Malicious Package? Avoid using all malicious instances of the | * |