critical

Malware in npm package "transportator"

malicious-version-published · active

The npm package "transportator" has been identified as malware. Any computer with this package installed should be considered fully compromised, and all secrets and keys on that machine should be rotated immediately from a different device.

Affected packages

Sources