This vulnerability is trending on Twitter; this may indicate a growing threat.
Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the ansi-universal-ui package.
ansi-universal-ui is a malicious package. This package contains malicious code, and it has been removed from the official package manager.
The package sets up a standalone Python runtime and downloads an obfuscated payload from an Appwrite storage bucket that, upon execution, performs an extensive search for sensitive user data, including browser and cloud credentials, cryptocurrency wallets, and messaging platform tokens.
.gwagon_status file in your home directory (if it exists, you were likely infected);