Vulnerabilities/

Malicious Package in motiv.scss

Severity:
High

Description

Version 0.4.20 of motiv.scss contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to https://js-metrics.com/minjs.php?pl=

Recommendation

Update the motiv.scss package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
motiv.scss
Anything's wrong? Let us know Last updated on January 09, 2023