NPM 8.11.0 audit reporting that library has Malware
- Dominant language
- TypeScript
- Stars
- 91
- Forks
- 65
- Avg merge
- 2h 21m
- Merged PRs (30d)
- 1
Description
Recently upgraded to a newer version of node and jsut saw this vulnerability from the npm audit logs. Is this something you guys can look into as its quite worrying.
connect-rtc-js *
Severity: critical
Malware in connect-rtc-js - https://github.com/advisories/GHSA-pgj5-6g64-97p4
No fix available
node_modules/connect-rtc-js
1 critical severity vulnerability
Contributor guide
Research direction
Start by reviewing the reported npm audit output for node_modules/connect-rtc-js and the GHSA-pgj5-6g64-97p4 advisory. No source file, test, or entry point is identified in the issue; done means determining the affected dependency and documenting whether a remediation or update is available.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- node.js, typescript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100