GMS-2020-16: Malicious Package
(updated )
of 8.9.4
contain malicious code as a preinstall script. The package reads the system’s SSH keys but does not upload it to a remote server. Remove the package from your environment. There is no evidence of further compromise at the moment.
References
Detect and mitigate GMS-2020-16 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →