Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the github.com/kaleidora/dnsub-scanning-tool package.
github.com/kaleidora/dnsub-scanning-tool is a malicious package. This package contains malicious code and while hile this package might be attempting to impersonate a legitimate DNS/subdomain scanning tool, there is no connection between that valid project and this package, which conceals a remote access trojan (RAT) and an infostealer. A malicious actor published this module as part of a larger GitHub malware lure network (tracked as Operation "Muck and Load") spanning over 222 repositories; this allowed the attacker to distribute a Windows malware-staging chain disguised as an active developer utility.