critical

Malware in npm package "vqlxjmpr"

malicious-version-published · active

The npm package "vqlxjmpr" has been identified as malicious. Any system where it was installed should be considered fully compromised, and all secrets and keys stored on that machine should be rotated immediately from a different computer.

Affected packages

Sources