ColemanGariety / gulp-nodemon

gulp + nodemon + convenience
526 stars 76 forks source link

Update Dependencies to Avoid Malicious Code #166

Closed spencerbeggs closed 5 years ago

spencerbeggs commented 5 years ago

Updates dependencies to latest versions to remove BitCoin-stealing code introduced by the flatmap-stream module that was included via nodemon. More info about the incident is here:

https://blog.npmjs.org/post/180565383195/details-about-the-event-stream-incident

Fixes #165

spencerbeggs commented 5 years ago

Yeah, it looks like you are not using the event-stream module at all I removed it from package.json and pushed the the branch. This PR overlaps with #165 and #164

evolmk commented 5 years ago

yes flatmap-stream has/had some malicious code (steal cryptocurrencies).

Bitdefender Notification:

... \flatmap-stream\index.min.js is infected with Trojan.JS.Agent.SYW and was moved to quarantine. It is recommended that you run a System Scan to make sure your system is clean.