critical

Malware in npm package ecto-flag-read-m7p2

malicious-version-published · active

The npm package ecto-flag-read-m7p2 has been identified as malware. Any system where it was installed should be considered fully compromised, and all secrets stored on that machine should be rotated immediately from a different computer.

Affected packages

Sources