NPM lib Pac-Resolver is downloaded 3m times a week – and it exposes apps to hijacking via evil proxy config
Pac mania
A popular NPM code library called Pac-Resolver has been updated to eliminate a severe remote-code execution vulnerability. Developers who have incorporated the package into their applications should make sure to update their dependencies to be rid of the bug, and provide necessary updates to users to secure them.…
from The Register
No comments