All versions of sdfjghlkfjdshlkjdhsfg contain malicious code. The package is essentially a worm that fetches all packages owned by the user, adds a script to self-replicate as a preinstall script and publishes a new version.
Remove the package from your environment and ensure all packages owned were not impacted.
{
"cwe_ids": [
"CWE-506"
],
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T18:46:18Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}