@opensearch-project/opensearch

npm Compromised

1

report

Attack type: Malicious version

Reports

Malicious version Versions: = 3.5.3 10d ago by isitcompromised.com

Malware in @opensearch-project/opensearch ## Overview The OpenSearch Project has sustained a security incident involving an external actor gaining force-push permissions within the project's CI infrastructure to embed malicious packages into four release versions of `@opensearch-project/opensearch`. Users are instructed to immediately take actions recommended in the **Remediation** section of this advisory. ## Affected Versions **Package**: `@opensearch-project/opensearch` | Version | Published (UTC) | Published (America/New_York) |

View evidence

Have more info?

Submit additional evidence or a new report for this package.

Submit a report