critical

Malware in npm package @snowsight/debug-tooling

malicious-version-published · active

The npm package @snowsight/debug-tooling has been identified as malware. Any system with this package installed should be considered fully compromised, and all secrets and keys on that machine should be rotated immediately from a separate, clean computer.

Affected packages

Sources