critical

Malware in npm package web3-common

malicious-version-published · active

The npm package web3-common has been identified as malicious. Any system with this package installed should be considered fully compromised, and all secrets and keys on that system must be rotated immediately from a separate, clean machine.

Affected packages

Sources