CRITICAL: 'pino-testkit@10.4.5' (npm) is a malicious typosquatting package with obfuscated code enabling arbitrary code execution. Remove & audit dependencies now. No CVE assigned. https:// radar.offs

CRITICAL: 'pino-testkit@10.4.5' (npm) is a malicious typosquatting package with obfuscated code enabling arbitrary code execution. Remove & audit dependencies now. No CVE assigned. https:// radar.offseq.com/threat/malici ous-code-in-pino-testkit-npm-da4f2d1960e5a45d # OffSeq # npm # SupplyChainSecurity # infosec

2 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CRITICAL: 'pino-testkit@10.4.5' (npm) is a malicious typosquatting package with obfuscated code enabling arbitrary code execution. Remove & audit dependencies now. No CVE assigned. https:// radar.offs

mastodon:infosec-exchangeother5d ago kagi ↗

CRITICAL: 'pino-testkit@10.4.5' (npm) is a malicious typosquatting package with obfuscated code enabling arbitrary code execution. Remove & audit dependencies now. No CVE assigned. https:// radar.offseq.com/threat/malici ous-code-in-pino-testkit-npm-da4f2d1960e5a45d # OffSeq # npm # SupplyChainSecurity # infosec

chromatitle npm v1.0.0 embeds CRITICAL malicious code: obfuscated JS fetches & executes remote payloads at import, risking system compromise. Remove & audit dependencies, no patch yet. No CVE. https:/

mastodon:infosec-exchangeother4d ago kagi ↗

chromatitle npm v1.0.0 embeds CRITICAL malicious code: obfuscated JS fetches & executes remote payloads at import, risking system compromise. Remove & audit dependencies, no patch yet. No CVE. https:// radar.offseq.com/threat/malici ous-code-in-chromatitle-npm-1cefd95c647d92b5 # OffSeq # npm # Malware # SupplyChain