-
Notifications
You must be signed in to change notification settings - Fork 1.7k
Open
Description
Recently published versions 20.0.4, 20.0.5, 20.0.6, 19.0.3 and 18.1.4 contain a post-install script bundle.js that seems to pull various tokens (GitHub, NPM, AWS, GCP) and attempts to exfiltrate cloud account secrets plus whatever trufflehog finds. 20.0.3 was also published with bundle.js but is missing package.json postinstall declaration.
These don't have matching tags on the repo, so publishing tokens have apparently leaked.
ng2-file-upload also looks affected.
edit: Affected versions are now gone from NPM.
tszewcow, patlkli, AntiPasha, samsonkumawong, pregress and 6 morefynnshpauhomspatricio-ezequiel-hondagneu-roig, profanis, ipranjic, thanjira-gulp, costas80 and 4 more
Metadata
Metadata
Assignees
Labels
No labels