Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using any version of flatmap-stream and version 3.3.6 of event-stream.
flatmap-stream is a malicious package which was used in order to steal bitcoins from wallets. The malicious code was able to check if the copay-dash package was installed, and then attempt to steal the bitcoins stored in it. It was distributed by hijacking the popular event-stream package and adding flatmap-stream as a dependency.
You can read more about the malicious code on our blog.
right9ctrl adds flatmap-stream as a dependency of the package event-stream and published version 3.3.6 or the package.right9ctrl rewrites the code to remove the dependency on flatmap-stream and pushes out a new version (4.0.0).event-stream.flatmap-stream package and removes version 3.3.6 of event-stream.