Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the agentgui package.
agentgui is a malicious package.
This package has been compromised as part of a malicious supply-chain attack linked to North Korean threat actors (Contagious Interview campaign / Lazarus APT group).
The legitimate package was hijacked, with intact functionality maintained to evade early detection. A malicious loader was hidden directly inside the existing database.js file.