CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. |
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. |
The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is known to record and track user information. The module tracks the following information. Source IP process.versions process.platform How the module was invoked (test, require, pre-install) |
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |