GMS-2020-502: Malicious Package
(updated )
All versions of sdfjghlkfjdshlkjdhsfg
contain malicious code. The package is essentially a worm that fetches all packages owned by the user, adds a script to self-replicate as a preinstall script and publishes a new version. ## Recommendation
Remove the package from your environment and ensure all packages owned were not impacted.
References
Detect and mitigate GMS-2020-502 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →