localForage / localForage-memoryStorageDriver

A volatile, in memory storage driver for localForage.
Other
17 stars 5 forks source link

Beware typo-squatting: Package with name all lowercase was malware #7

Open RPCMoritz opened 2 years ago

RPCMoritz commented 2 years ago

See this GHSA My brief look at the code/npm repo indicate nothing overly untoward, there is no public discussion regarding this issue - yet it's being listed with a fairly stark warning.

Does anyone have any insights what's going on here?

RPCMoritz commented 2 years ago

I've added it to this thread of likely similar issues.

RPCMoritz commented 2 years ago

Okay, looks like classic typo-squatting - camelCase matters.

Fonger commented 2 years ago

Thanks for the clarification. Maybe you can keep this issue open so others can rest assured if it's a false postivie

RPCMoritz commented 2 years ago

I've reworded it a bit, so the information is more accessible.