This package is in our known-malicious corpus. Details below.
Flagged as malicious
malware, affects all versions
cvss
9.0
how bad it is if exploited, out of 10
epss
not scored
chance of exploitation in the next 30 days
xyz score
4.0
CyberXYZ composite, out of 10
fig. 01 — GHSA-43vf-2x6g-p2m5, the advisory selected below
// advisories
GHSA-43vf-2x6g-p2m5
CRITICAL
Version 16.3.3 of browserift contained malicious code as a preinstall script. The package was a backdoor that opened a connection to a remote server and executed incoming commands on both Unix and Windows machines