Описание
Malicious Package in maybemaliciouspackage
All versions of maybemaliciouspackage contain malicious code. The package prints the system's SSH keys to the console as a postinstall script.
Recommendation
Remove the package from your environment. There are no further signs of compromise.
Пакеты
Наименование
maybemaliciouspackage
npm
Затронутые версииВерсия исправления
>= 0.0.0
Отсутствует
9.8 Critical
CVSS3
Дефекты
CWE-506
9.8 Critical
CVSS3
Дефекты
CWE-506