Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the mbt package.
mbt is a [ that triggers an 11.6 MB heavily obfuscated script (execution.js) during package installation. Once executed on a developer's machine, the malware steals the developer's credentials and weaponizes them to automatically create public GitHub repositories under the victim's account. These auto-generated repositories carry the hardcoded description "A Mini Shai-Hulud has Appeared" and serve as a live data exfiltration channel.