Description
Version 0.1.7 of scroool contained malicious code. The code when executed in the browser would enumerate password, cvc and cardnumber fields from forms and send the extracted values to https://js-metrics.com/minjs.php?pl=
Recommendation
No fix is available yet. Followings are affected versions:
- = 0.1.7
References
Could your website be exposed too?
SmartScanner can check your website for Malicious Package in scroool and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Malicious Package in device-mqtt - Vulnerability
- Malicious Package in json-serializer - Vulnerability
- Malicious Package in rate-map - Vulnerability
- Malicious Package in zemen - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated July 27, 2023


