See Bounty. This is now being flagged when you do an npm audit on this repo https://huntr.dev/bounties/8cf8cc06-d2cf-4b4e-b42c-99fafb0b04d0/