Skip to content

[possible malware alert] forked package log-electron contains a possibly-malicious payload loader. #419

@minho-comcom-ai

Description

@minho-comcom-ai

https://github.com/carfulot/log-electron was forked from this repo and published via npmjs (https://www.npmjs.com/package/log-electron).

Renaming PR contains the malware loader code: https.request(logPkgJson.testing and the payload location: https://raw.githubusercontent.com/carfulot/log-electron/master/src/core/testing in package.json

CC: @megahertz @github @npm

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions