Skip to content

a package possibly imitating atomico #83

Description

@tamir-ben

Hi, my name is Tamir and I'm a security researcher at Mend.io

I have noticed something strange, I would be happy to get clarifications from you.

the package https://www.npmjs.com/package/atomico-base is pretending to be atomico, while also pretending to be @UpperCod , the creator of Atomico.

image

the npm user also does not match https://www.npmjs.com/~uppercod

Thanks in advance!

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions