GHSA-33gc-f8v9-v8hm

Suggest an improvement
Source
https://github.com/advisories/GHSA-33gc-f8v9-v8hm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-33gc-f8v9-v8hm/GHSA-33gc-f8v9-v8hm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-33gc-f8v9-v8hm
Published
2020-09-01T20:41:40Z
Modified
2021-10-01T13:27:36Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Malicious Package in ladder-text-js
Details

ladder-text-js contained a malicious script that attempted to delete all files when npm test was run.

Recommendation

This module has been unpublished from the npm Registry. If you find this module in your environment remove it.

Database specific
{
    "cwe_ids":  [
        "CWE-506"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:31:21Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / ladder-text-js

Package

Name
ladder-text-js
View open source insights on deps.dev
Purl
pkg:npm/ladder-text-js

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-33gc-f8v9-v8hm/GHSA-33gc-f8v9-v8hm.json"