@things-factory/attachment-base 9.0.43
Embedded secret exfiltration script
Detects a supply chain compromise in NPM packages (TinyColor, CrowdStrike etc.)Downloads latest trufflehog release
SHA-25619445b925e82bc467c30a848a3342611f5d8213ac2ff20c110f4b7c837561c9f
Also flagged by osv (MAL-2025-47282: Malicious code in @things-factory/attachment-base (npm)) +2 more.