Nexodus Archive: Fediverse


<p>simple-swizzle@0.2.3 is *still* public, active, and in the wild. You can see the malicious code on the code browser: <a href="https://www.npmjs.com/package/simple-swizzle/v/0.2.3?activeTab=code" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://www.</span><span class="ellipsis">npmjs.com/package/simple-swizz</span><span class="invisible">le/v/0.2.3?activeTab=code</span></a></p><p>Edit: seeing folks boost this one still but editing to say that it’s been resolved</p> A screenshot of the npm package page for simple-swizzle v0.2.3 The compromised code starts with