critical

Malware in npm package @vivaux/telemetry

malicious-version-published · active

The npm package @vivaux/telemetry has been found to contain malware. Any system with this package installed should be considered fully compromised, and all secrets and keys on that system should be rotated immediately from a different machine.

Affected packages

Sources