Description
The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0794 | The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets. |
Github GHSA |
GHSA-hm6q-r2jc-cpqh | lodahs is malware |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:25:12.676Z
Reserved: 2019-12-12T00:00:00.000Z
Link: CVE-2019-19771
No data.
Status : Modified
Published: 2019-12-12T20:15:17.867
Modified: 2024-11-21T04:35:21.190
Link: CVE-2019-19771
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA