critical

Malware in npm package ozonex-sdk (GHSA-v2hc-cmv5-999p)

malicious-version-published · active

The npm package ozonex-sdk was found to contain malware. Any system with this package installed should be considered fully compromised, and all secrets and keys stored on it should be rotated immediately from a separate, clean machine.

Affected packages

Sources