critical

Malware in npm package ecto-spectral-leak-8d4e2

malicious-version-published · active

The npm package ecto-spectral-leak-8d4e2 has been identified as malware. Any system with this package installed should be considered fully compromised, and all secrets and keys on that system should be rotated immediately from a different computer.

Affected packages

Sources