critical

Malware in npm package "rate-limits-flexible"

malicious-version-published · active

A malicious npm package named "rate-limits-flexible" was published containing malware. Any system where it was installed should be considered fully compromised, and all secrets stored on that machine should be rotated immediately from a different computer.

Affected packages

Sources