▲ | 9dev 4 days ago | |||||||
Irritatingly, this doesn't turn up anything, despite having a theoretically-compromised project as per the package-lock.json… At least on my end | ||||||||
▲ | mewpmewp2 4 days ago | parent | next [-] | |||||||
What do you mean irritatingly? Do you mean that you think 'grep -r "_0x112fa8"' is not enough or are you irritated that npm audit is flagging as if it was compromised? | ||||||||
| ||||||||
▲ | AgentME 4 days ago | parent | prev [-] | |||||||
If you had the dependency installed before this attack, then you would still be pinned to an old safe version. |