We Just Found Malicious Code in the Popular NPM Package
by macbudkowski.eth5759 🥝10mosubstack.com
avatar
Sindresohrus asked ChatGPT what the malware does: https://github.com/chalk/chalk/issues/656#issuecomment-3266900029
avatar
For anyone trying to find the packages which are affected, here is (apparently) the npm maintainer who got pwned and tells which packages contain bad code https://news.ycombinator.com/item?id=45169794

avatar
I did a bunch of checks and from what I can tell, this version of Kiwi News is, for now unaffected of the issues
Characters remaining: 10,000

comment guidelines