Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the typo-crypto package.
typo-crypto is a malicious package.
This package contains a trojanized core.js file mimicking the legitimate core-js package. The malware activates when it receives a hash input beginning with 0098273, then downloads a second-stage payload from a hardcoded C2 server and runs Windows, macOS, or Linux specific behavior, concealing itself with base64 plus an XOR cipher keyed to 01042025 and maintaining file-based persistence with payload rotation.
Note: This package's malicious behavior may be linked to that of the compromised versions of chalk, debug, and axios.