GHSA-qv78-398w-cxp7
CRITICALAll versions of shrugging-logging contain malicious code as a postinstall script. The package fetches all names of npm packages owned by the user and attempts to add another maintainer to every package as a means of package hijacking,
- Affected
- >= 0, >=0
- Fixed in
- not stated
- Weakness
- CWE-506
- Published
- 2020-09-11
- Source
- github