Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the html-to-gutenberg package.
html-to-gutenberg is a Transform any valid HTML string into fully editable WP Gutenberg blocks in seconds rather than hours.
Affected versions of this package are vulnerable to Embedded Malicious Code. This release contains a multi-stage, blockchain-C2 remote code execution loader in .vscode/tasks.json that runs when the package folder is opened in VS Code. The obfuscated payload is delivered in font files and attempts to steal cryptocurrency in an EtherHiding-style attack.