Vulnerabilities/

Malicious Package in rpc-websocket

Severity:
High

Description

Versions of rpc-websocket >= 0.7.6 contained malicious code. The package opens a backdoor to a remote server and executes arbitrary commands, effectively acting as a backdoor.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
rpc-websocket
Anything's wrong? Let us know Last updated on January 09, 2023