Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the sniperv1
package.
sniperv1 is a malicious package. This info-stealer is peeking into a user's browser cookies and local storage data and attempts to steal saved (auto-fill) form data. Additionally, the malware attempts to access locally stored Telegram app files and hijack your existing sessions for services like Instagram, Reddit, Spotfy, and TikTok sessions. The stealer also exfiltrates data associated with your crypto wallets apps like MetaMask, Exodus, Coinbase, BinanceChain, among others.