GHSA-353r-3v84-9pjj

Suggest an improvement
Source
https://github.com/advisories/GHSA-353r-3v84-9pjj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-353r-3v84-9pjj/GHSA-353r-3v84-9pjj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-353r-3v84-9pjj
Published
2020-09-01T20:40:36Z
Modified
2021-10-01T13:25:56Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Malicious Package in nothing-js
Details

nothing-js contained a malicious script that attempted to delete all files when npm test was run.

Recommendation

This module has been unpublished from the npm Registry. If you find this module in your environment remove it.

Database specific
{
    "cwe_ids":  [
        "CWE-506"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:31:19Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / nothing-js

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-353r-3v84-9pjj/GHSA-353r-3v84-9pjj.json"