Description
Version 0.4.20 of motiv.scss contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to https://js-metrics.com/minjs.php?pl=
Recommendation
Update the motiv.scss package to the latest compatible version. Followings are version details:
- Affected version(s): = 0.4.20
- Patched version(s): 0.4.21
References
Could your website be exposed too?
SmartScanner can check your website for Malicious Package in motiv.scss and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Malicious Package in radic-util - Vulnerability
- Malicious Package in scroool - Vulnerability
- Malicious Package in github-jquery-widgets - Vulnerability
- Malicious Package in another-date-picker - Vulnerability


