We found results for “


Good to know:


Date: April 18, 2022

The package 'epic-ue-loading' in NPM is malicious. The package was uploaded first time in April 18th 2022. All versions are malicious. The malicious package is exfiltrating user information like env variables and sends it out via a pipe-dream webhook. The package seems to target consumers of packages by the user 'spicywombat': https://www.npmjs.com/~spicywombat

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Embedded Malicious Code


Top Fix


Upgrade Version

No fix version available

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us