Version 0.1.1 of flatmap-stream is considered malicious.
This module runs an encrypted payload targeting a very specific application, copay and because they shared the same description it would have likely worked for copay-dash.
The injected code:
The decrypted data was part of a module, which was then compiled in memory and executed.
This module performed the following actions:
The chunk of code that was written out was the actual malicious code, intended to be run on devices owned by the end users of Copay.
This code would do the following:
If you find this module in your environment it's best to remove it. The malicious version of event-stream and flatmap-stream have been removed from the npm Registry.
{
"cwe_ids": [
"CWE-506"
],
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T18:33:59Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}