The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:25:12.676Z

Reserved: 2019-12-12T00:00:00

Link: CVE-2019-19771

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-12T20:15:17.867

Modified: 2024-11-21T04:35:21.190

Link: CVE-2019-19771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.