Description
The openssl.js
package is a piece of malware that steals environment variables and sends them to attacker controlled locations.
All versions have been unpublished from the npm registry.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0.0.0
References
Related Issues
- Code Injection in cryo - CVE-2018-3784
- Open Redirect in urijs - CVE-2022-0868
- Code Injection in mosc - CVE-2020-7672
- Code Injection in jsen - CVE-2020-7777
- Tags:
- npm
- openssl.js
Anything's wrong? Let us know Last updated on September 07, 2023