Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the @meme-sdk/trade package.
@meme-sdk/trade is a malicious package. This package contains malicious code, and its content was not yet removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.
This package is linked to Contagious Interview campaign and the fraudulent IT Worker scam according to ReversingLabs. The attack uses a multi-layered approach, where the first layer packages don’t contain the malicious code, but import the second layer packages that contain the malicious functionality. The latter packages are disposable and easily replaced once detected or removed from npm.