CVE-2017-16204
Vulnerability Description
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.