GHSA-w3f3-4j22-2v3p

Suggest an improvement
Source
https://github.com/advisories/GHSA-w3f3-4j22-2v3p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-w3f3-4j22-2v3p/GHSA-w3f3-4j22-2v3p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w3f3-4j22-2v3p
Published
2020-09-02T21:27:02Z
Modified
2021-09-30T21:25:19Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Malicious Package in destroyer-of-worlds
Details

The package destroyer-of-worlds contained malicious code. The package contained a bash script that was run as a postinstall script. The script deleted system files and attempted to exhaust resources by creating a large file, a fork bomb and an endless loop. The script targeted UNIX systems.

Recommendation

Remove the package from your environment and perform additional incident response on your system's files and processes.

Database specific
{
    "cwe_ids": [
        "CWE-506"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-08-31T18:39:31Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
}
References

Affected packages

npm / destroyer-of-worlds

Package

Name
destroyer-of-worlds
View open source insights on deps.dev
Purl
pkg:npm/destroyer-of-worlds

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-w3f3-4j22-2v3p/GHSA-w3f3-4j22-2v3p.json"