Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the pino-sdk-v2 package.
pino-sdk-v2 is a malicious package.
This package contains malicious code. An obfuscated payload in lib/tools.js that scans .env, .env.local, .env.production, .env.development, and .env.examplefiles for secrets and exfiltrates them to a Discord webhook on require(). While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.