Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for npmpubman
.
npmpubman is a malicious package.
All versions of npmpubman
contain malicious code. The index.js
file sends local environment variables to a remote server. The file is not run upon installation - the package needs to be required or the index.js
run manually.