Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the @qlik/carbon-core package.
Affected versions of this package are vulnerable to Embedded Malicious Code. This package was involved in a supply chain compromise that affected multiple namespaces on the npm registry, including popular caching and key-value storage utilities. A malicious actor compromised a maintainer’s account or CI pipeline, allowing them to publish tampered versions across dozens of packages. The payload subsequently acted as a self-propagating worm by harvesting developer tokens from compromised environments and republishing new infected packages across other organizations.
The compromised packages contain an obfuscated dropper script (setup.mjs) that silently downloads the Bun JavaScript runtime to execute a secondary payload (often named Math_Symbol.js). The malware focuses on extensive credential theft, extracting AWS, GCP, Azure, npm, HashiCorp Vault, and Kubernetes secrets, and can scrape GitHub Actions runner memory. Furthermore, it appears to install a dead-man's switch designed to execute additional attacker-controlled commands as soon as the stolen GitHub token is revoked. Data is exfiltrated securely using encrypted GitHub Actions artifacts and dead-drop repositories, meaning no malicious C2 domains will appear in standard network logs.