GMS-2020-363: Malicious Package
(updated )
All versions of maleficent
contain malicious code. The package is a demonstration of possible risks when installing npm packages. It gathers system information such as: environment variables, OS information, network interface, AWS credentials, npm credentials and ssh keys. The package prints the information to a local file but does not upload it to a remote server.
Remove the package from your environment. There is no further compromise.
References
Detect and mitigate GMS-2020-363 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →