Current versions of the monitoring software Checkmk close a cross-site scripting vulnerability classified as a critical risk.
The npm packages were available since July, have elaborately obfuscated malicious routines, and rely on a fake CAPTCHA to ...