-
-
Notifications
You must be signed in to change notification settings - Fork 62
Open
Labels
bugSomething isn't workingSomething isn't working
Description
Describe the bug.
Hello,
Multiple new versions of the package have been published on NPM. These new versions adds bun_environment.js 10Mo.
List of new versions:
- 6.8.3
- 6.9.1
- 6.8.2
- 6.10.1
I find nothing on this github repository linking to these new releases.
I also find nothing in the source code that links to bun_environment.js.
I think it starts a trufflehog process which scan for secrets...
I am not sure but my search came to this package.
Is the package compromised?
See the hasInstallScripts set to true? It can launch malware with that.
Expected behavior
No malware
Screenshots
How to Reproduce
- I first did this
- I then did this
- And so on . . .
🖥️ Device Information [optional]
- Operating System (OS):
- Browser:
- Browser Version:
👀 Have you checked for similar open issues?
- I checked and didn't find similar issue
🏢 Have you read the Contributing Guidelines?
- I have read the Contributing Guidelines
Are you willing to work on this issue ?
None
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working