critical

Malware in npm package forge-jsx2

malicious-version-published · active

The npm package forge-jsx2 has been identified as containing malware. Any system with this package installed should be considered fully compromised, and all secrets and keys on that system should be rotated immediately from a different machine.

Affected packages

Sources