Critical severity vulnerability that affects event-stream and flatmap-stream
Critical severity
GitHub Reviewed
Published
Nov 26, 2018
to the GitHub Advisory Database
•
Updated Jan 12, 2023
The NPM package
flatmap-stream
is considered malicious. A malicious actor added this package as a dependency to the NPMevent-stream
package in version3.3.6
. Users ofevent-stream
are encouraged to downgrade to the last non-malicious version,3.3.4
, or upgrade to the latest 4.x version.Users of
flatmap-stream
are encouraged to remove the dependency entirely.References