Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @bmw-fedev/auth to version 0.0.2 or higher.
@bmw-fedev/auth is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.
Note:
The ownership of the public package was claimed by legitimate authors and NPM removed "security holding" status.