Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the @openwebconcept/design-tokens package.
@openwebconcept/design-tokens is a Shared design tokens for NL Design System
Affected versions of this package are vulnerable to Embedded Malicious Code that injects a credential-harvesting script that runs via postinstall on every npm install. It demonstrates TeamPCP-style CanisterWorm behaviour by re-injecting itself into every package whose token it harvested, propagating the compromise further.