Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the secbg
package.
secbg is a malicious package.
it imports the malicious secrevtwo
package upon install which contains an obfuscated TCP
reverse shell for *nix
machines that will execute when the dist_util
module is imported.