critical

Malware in npm package @hatcha-captcha/core

malicious-version-published · active

The npm package @hatcha-captcha/core was found to contain malware. Any system with this package installed should be considered fully compromised, and all secrets and keys stored on that system should be rotated immediately from a separate, clean computer.

Affected packages

Sources