critical

Malware in npm package "hex-type"

malicious-version-published · active

The npm package "hex-type" has been identified as malware. Any system where it was installed should be considered fully compromised, and all secrets and keys on that system should be rotated immediately from a different machine.

Affected packages

Sources