You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Jan 13, 2023. It is now read-only.
Hey, I'm a security researcher from https://mend.io
This malicious code was found by us at https://Mend.io using our Supply Chain Defender technology
Looking at the diff here: https://my.diffend.io/npm/@dydxprotocol/solo/0.41.0/0.41.1
A preinstall was added:
but this script contains a code that looks malicious:
it seems to be stealing credentials and other secrets.
This applies to other packages of the ecosystem as well.