GHSA-vv52-3mrp-455m

Suggest an improvement
Source
https://github.com/advisories/GHSA-vv52-3mrp-455m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-vv52-3mrp-455m/GHSA-vv52-3mrp-455m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vv52-3mrp-455m
Published
2020-09-03T15:53:36Z
Modified
2020-08-31T19:01:56Z
Summary
Malicious Package in m-backdoor
Details

All versions of m-backdoor contain malicious code. The package downloads a file from a remote server and executes it as a preinstall script. At the time of the release of this advisory the downloaded file only defaces websites by removing elements randomly from the DOM.

Recommendation

Remove the package from your system.

Database specific
{
    "cwe_ids": [
        "CWE-506"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-08-31T19:01:56Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
}
References

Affected packages

npm / m-backdoor

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-vv52-3mrp-455m/GHSA-vv52-3mrp-455m.json"