critical

Malware in npm package crypto-hash-sdk

malicious-version-published · active

The npm package crypto-hash-sdk has been identified as containing malware. Any system where it was installed should be considered fully compromised, and all secrets and keys on that system should be rotated immediately from a different computer.

Affected packages

Sources