An open API service providing security vulnerability metadata for many open source software ecosystems.

MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBqOTctajU5Ny1wcG03

Critical

Malicious Package in rqeuest

Affected Packages Affected Versions Fixed Versions
npm:rqeuest
PURL: pkg:npm/rqeuest
>= 0 No known fixed version
0 Dependent packages
1 Dependent repositories
3 Downloads last month

Affected Version Ranges

All affected versions

0.0.1-security

All versions of rqeuest typosquatted a popular package of similar name and tracked users who had installed the incorrect package. The package uploaded information to a remote server including: name of the downloaded package, name of the intended package, the Node version and whether the process was running as sudo. There is no further compromise.

Recommendation

Remove the package from your dependencies and always ensure package names are typed correctly upon installation.

References: