critical

Malware in npm package apple-mycelium-fix

malicious-version-published · active

The npm package "apple-mycelium-fix" has been identified as malware. Any system that installed or ran this package should be considered fully compromised, and all secrets and keys on that system should be rotated from a different, clean machine.

Affected packages

Sources