A hidden backdoor was found in the server code that:
- Steals all server secrets (API keys, database credentials, JWT secrets) and sends them to an external server
- Downloads and runs arbitrary code from that external server on your machine
- Runs automatically every time the server starts — no user action needed