Severity: Critical
CVSS Score: 9.8
The package `donotinstallthis` contained malicious code. The package contained a script that was run as part of the install script. The script contacted a remote service tracking how many installations were done. There is no further compromise. ## Recommendation Remove the package from your environment.