CVE Vulnerabilities

CVE-2017-16128

Embedded Malicious Code

Published: Jun 07, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.

Weakness

The product contains code that appears to be malicious in nature.

Affected Software

Name Vendor Start Version End Version
Npm-script-demo Npm-script-demo_project 0.0.1 (including) 0.0.1 (including)

Potential Mitigations

References