-
Notifications
You must be signed in to change notification settings - Fork 2.6k
Closed
Description
Current Behavior
I just saw an automated update PR created by Renovate in one of my repos containing update for nx
to version 21.7.0
.
The latest version on NPM is indeed 21.7.0
and it was published ~11 minutes ago.
However this version isn't present in GitHub releases.

Looking at the diff, it seems like it contains some kind of malware that gathers information about the system, checks for available CLIs and makes some GitHub requests? 😕


Expected Behavior
I expect this to be un-published.
GitHub Repo
No response
Steps to Reproduce
Just check the latest version on NPM.
Nx Report
Not relevant.
Failure Logs
Package Manager Version
No response
Operating System
- macOS
- Linux
- Windows
- Other (Please specify)
Additional Information
No response
Ccccclong, gaurav6386, nyzss, sulewicz and MartinCuraftzi