Vulnerabilities/

openssl.js is malware

Severity:
High

Description

The openssl.js package is a piece of malware that steals environment variables and sends them to attacker controlled locations.

All versions have been unpublished from the npm registry.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
openssl.js
Anything's wrong? Let us know Last updated on September 07, 2023

This issue is available in SmartScanner Professional

See Pricing