More than 723,000 projects use cryptographic libraries (aes-js and pyaes) with insecure defaults.

According to Trail of Bits, the issue has been known to the developers since 2022 but was never fixed.