critical

Malware in npm package get-deps-path

malicious-version-published · active

The npm package get-deps-path was published containing malware. Any system where it was installed should be treated as fully compromised, and all secrets and keys on that machine should be rotated immediately from a different computer.

Affected packages

Sources