Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using github.com/mprogrammer2020/snipper-bot-uniswap altogether.
Affected versions of this package are vulnerable to Embedded Malicious Code. This package contains malicious code and was identified as part of the PolinRider supply chain campaign, linked to North Korean threat actors associated with the Contagious Interview/Famous Chollima activity cluster. The malicious code takes the form of an obfuscated JavaScript loader, hidden either inside configuration files or disguised as a fake .woff2 font file, and triggered through developer tooling. Once executed, the loader is designed to contact public blockchain RPC infrastructure (TRON, Aptos, BNB Smart Chain) to retrieve an encrypted second-stage payload, decrypt it using an embedded XOR key, and execute it via eval().