Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the pgserve package.
pgserve is an Embedded PostgreSQL server with true concurrent connections - zero config, auto-provision databases
Affected versions of this package are vulnerable to Embedded Malicious Code that injects a credential-harvesting script that runs via postinstall on every npm install. It demonstrates supply-chain worm behaviour by re-injecting itself into every package which npm token it harvested, propagating the compromise further.