Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the secmeasure
package.
secmeasure is a malicious package.
This package contains malicious code, and its content was removed from the official package manager. The sisaws
package leverages "typosquatting" for the legitimate sisa
package, targeting Sistema Integrado de Información Sanitaria Argentino (SISA) API integration. The attack is design to deliver a Remote Access Trojan (RAT) dubbed as SilentSyncof
which attempts remote command execution, file exfiltration, screen capturing, and web browser data theft.