Advisories for Npm/Db-Evo package

2025

Malicious code in db-evo (npm)

This package was compromised by the Shai-Hulud NPM worm. The malicious payload steals tokens and credentials and publishes them to GitHub before propogating itself to NPM packages the user owns.