Skip to content

NPM Package Repository linking to potential malicious repo #113

@pedromsilvapt

Description

@pedromsilvapt

Hey there @j-holub

Is this NPM package the official one?
https://www.npmjs.com/package/node-mpv

Because if it is, it is linking to a GitHub Repo that seems to have been taken over by someone else:
https://github.com/00SteinsGate00/Node-MPV

It then auto-redirects to:
https://github.com/1oginov/Node-MPV/

And it seems like something fishy is going one there. I'm not a security researcher or anything, and I didn't want to go too deep on this, but this commit looks pretty sketchy to me.
1oginov/Node-MPV@e380d4e

I know you probably don't work actively on this project anymore, but if you still have access to the NPM account for that project, and could just update the link, it could save some people from cloning the wrong repo.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions