critical

Malware in npm package tw-fluid-type (GHSA-53h7-3qgm-jr76)

malicious-version-published · active

The npm package tw-fluid-type was published with embedded malware. Any system with this package installed should be considered fully compromised, and all secrets and keys on that system must be rotated immediately from a different machine.

Affected packages

Sources