Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the loquru
package.
loquru is a malicious package.
This package contains a malicious code and uses "typosquatting" to bait unaware users to install it.
The malicious loquru
package pretends to be the popular loguru
library. It hides malicious code within a string of whitespace, which is executed upon import, leading to the download and execution of further scripts from a remote server, with one script attempting to run with root privileges.