Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the relative-ci-agent
package.
relative-ci-agent is a malicious package. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship. The bin script in this package collects environment variables from process.env and sends them to a remote endpoint controlled by a malicious actor.