Malware in npm package truffle-helper (GHSA-6qhx-9853-hxm6)
malicious-version-published · active
The npm package "truffle-helper" has been flagged as containing malware. Any system where this package was installed should be considered fully compromised, and all secrets and keys on that system should be rotated from a separate, clean machine.
Affected packages
- npmtruffle-helper