critical

Malware in npm package typeorm-encrypt

malicious-version-published · active

The npm package typeorm-encrypt has been flagged as containing malware. Any system with this package installed should be treated as fully compromised, and all secrets and keys on it should be rotated immediately from a separate, clean machine.

Affected packages

Sources