Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the react-zutils
package.
react-zutils is a malicious package.
This is a complex, multi-stage, obfuscated malware targeting developers' machines. Upon installation, this package spawns a detached process that attempts to locate, collect, and exfiltrate sensitive data from several crypto wallet browser extensions, including Metamask, Phantom, and Coinbase. The malware specifically targets log and database files (.log
and .ldb
), which can contain private keys, seed phrases, and other sensitive information. It uploads these files, along with machine information, to a remote server via an ngrok endpoint.