Description
Version 1.3.2 of geoheat contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to https://js-metrics.com/minjs.php?pl=
Recommendation
No fix is available yet. Followings are affected versions:
- = 1.3.2
References
Related Issues
- Malicious Package in device-mqtt - Vulnerability
- Malicious Package in json-serializer - Vulnerability
- Malicious Package in rate-map - Vulnerability
- Malicious Package in zemen - Vulnerability
You might also like:
- Tags:
- npm
- geoheat
Anything's wrong? Let us know Last updated on July 27, 2023


