critical

Malware in npm package rsflows-pexml

malicious-version-published · active

The npm package rsflows-pexml has been identified as malware. Any system where it was installed should be considered fully compromised, and all secrets and keys stored on that machine should be rotated immediately from a separate, clean computer.

Affected packages

Sources