Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upBackdoored dependency? flatmap-stream-0.1.1 and flatmap-stream-0.1.2 #115
Comments
NewEraCracker
referenced this issue
Nov 19, 2018
Closed
Backdoored sub-dependency? flatmap-stream-0.1.1 and flatmap-stream-0.1.2 #1451
This comment has been minimized.
This comment has been minimized.
kevinburke
commented
Nov 26, 2018
|
If you're reading this, it looks like the solution for the moment is to downgrade to 3.3.4 (which does not have the vulnerability) until npm support can grant permission to a new owner who won't inject compromised packages. |
pushed a commit
to SinS3i/gulp-vinyl-zip
that referenced
this issue
Nov 26, 2018
SinS3i
referenced this issue
Nov 26, 2018
Open
Update dependencies to address security vulnerabilities present #13
This comment has been minimized.
This comment has been minimized.
funny-falcon
commented
Nov 26, 2018
|
Thrre were no bad intentions: |
phillipperalez
referenced this issue
Nov 26, 2018
Open
lock event-stream to non-compromised version 3.3.4 #222
This comment has been minimized.
This comment has been minimized.
kevinburke
commented
Nov 26, 2018
|
per the description linked here: #116 (comment) the package attempts to steal Bitcoin from an installed Bitcoin wallet, so yes, it does seem like there were really bad intentions!!! |
This comment has been minimized.
This comment has been minimized.
funny-falcon
commented
Nov 26, 2018
|
I mean flatmap-stream were added to this repository not to steal bitcoins but to implement functionality. @right9ctrl just didn't know flatmap were malicious. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
NewEraCracker commentedNov 19, 2018
I'm using version 3.3.6 of this module. flatmap-stream was added by this commit:
e316336
The new updates to the package on npm are very suspicious.
0.1.0: https://registry.npmjs.org/flatmap-stream/-/flatmap-stream-0.1.0.tgz
0.1.1: https://registry.npmjs.org/flatmap-stream/-/flatmap-stream-0.1.1.tgz
0.1.2: https://registry.npmjs.org/flatmap-stream/-/flatmap-stream-0.1.2.tgz
Regards.