Vulnerabilities/

Malicious Package in geoheat

Severity:
High

Description

Version 1.3.2 of geoheat contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to https://js-metrics.com/minjs.php?pl=

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
geoheat
Anything's wrong? Let us know Last updated on July 27, 2023