Incident tracker · 26 Nov 2018

Are you exposed to the event-stream / flatmap-stream backdoor (November 2018)?

A new maintainer added 'flatmap-stream' as a nested dependency; it shipped a backdoor that exfiltrated Bitcoin wallet credentials from the Copay app.

Confirmed-compromised packages2 packages
npm
flatmap-streamcompromised: 0.1.1
npm
event-streamcompromised: 3.3.6
Advisory / post-mortem ↗
Check your repo

CodeTrawl matches your repo’s declared dependencies against this list. Analyze a repo, then open its Security tab — an exposure to this incident shows as a dated, cited finding. Matching is manifest-scoped: it catches a compromised name@version you still declare.

Analyze a repo