GMS-2020-346: Malicious Package
(updated )
of load-from-cwd-or-npm
contains malicious code. The malware breaks functionality of the purescript-installer
package by injecting targeted code. ## Recommendation
There is no indication of further compromise.
References
Detect and mitigate GMS-2020-346 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →