GMS-2020-253: Malicious Package
(updated )
All versions of evil-package
contain malicious code. The package uploads the contents of process.env
to example.com/log
. Remove the package from your environment. Given the host where the information was uploaded to there is no further indication of compromise.
References
Detect and mitigate GMS-2020-253 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →