critical

Malware in npm package truffle-helper (GHSA-6qhx-9853-hxm6)

malicious-version-published · active

The npm package "truffle-helper" has been flagged as containing malware. Any system where this package was installed should be considered fully compromised, and all secrets and keys on that system should be rotated from a separate, clean machine.

Affected packages

Sources