Описание
Malicious Package in destroyer-of-worlds
The package destroyer-of-worlds contained malicious code. The package contained a bash script that was run as a postinstall script. The script deleted system files and attempted to exhaust resources by creating a large file, a fork bomb and an endless loop. The script targeted UNIX systems.
Recommendation
Remove the package from your environment and perform additional incident response on your system's files and processes.
Пакеты
Наименование
destroyer-of-worlds
npm
Затронутые версииВерсия исправления
Отсутствует
9.8 Critical
CVSS3
Дефекты
CWE-506
9.8 Critical
CVSS3
Дефекты
CWE-506