GHSA-8hq2-fcqm-39hq

Suggest an improvement
Source
https://github.com/advisories/GHSA-8hq2-fcqm-39hq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-8hq2-fcqm-39hq/GHSA-8hq2-fcqm-39hq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8hq2-fcqm-39hq
Published
2020-09-02T21:46:05Z
Modified
2021-09-30T21:57:22Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Malicious Package in rimrafall
Details

Version 1.0.0 of rimrafall contains malicious code as a preinstall script. The package attempts to remove all files in the system's root folder.

Recommendation

If you installed this package it is likely your machine was erased. If not, remove the package from your system and verify if any files were deleted.

Database specific
{
    "cwe_ids":  [
        "CWE-506"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:40:20Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / rimrafall

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-8hq2-fcqm-39hq/GHSA-8hq2-fcqm-39hq.json"