Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using any version of flatmap-stream
and version 3.3.6
of event-stream
.
flatmap-stream
is a malicious package which was used in order to steal bitcoins from wallets. The malicious code was able to check if the copay-dash
package was installed, and then attempt to steal the bitcoins stored in it. It was distributed by hijacking the popular event-stream
package and adding flatmap-stream
as a dependency.
You can read more about the malicious code on our blog.
right9ctrl
adds flatmap-stream
as a dependency of the package event-stream
and published version 3.3.6 or the package.right9ctrl
rewrites the code to remove the dependency on flatmap-stream
and pushes out a new version (4.0.0).event-stream
.flatmap-stream
package and removes version 3.3.6 of event-stream
.