Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade got-fetch
to version 6.0.0 or higher.
got-fetch is a malicious package. through an npm postinstall script 'install.js'. A malicious actor compromised the credentials of one of the maintainers via a phishing attack; This allowed the attacker to publish tampered versions of the package to npm.
The script attempts to execute a malicious payload in 'crashreporter.dll', which is included in the package, using rundll32
on Windows systems.
Notes: