Description
opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.2.1
References
Related Issues
- d3.js is malware - CVE-2017-16044
- openssl.js is malware - CVE-2017-16065
- Arbitrary Code Execution in mathjs - mathjs - CVE-2017-1001002
- Moderate severity vulnerability that affects marked - CVE-2017-17461
You might also like:
- Tags:
- npm
- opencv.js
Anything's wrong? Let us know Last updated on September 07, 2023


