critical

Malware in npm package @johntaohunter/forge-jsx

malicious-version-published · active

The npm package @johntaohunter/forge-jsx has been flagged as containing malware. Any machine where this package was installed or run should be considered fully compromised, and all secrets and keys on that machine should be rotated immediately from a different computer.

Affected packages

Sources