GHSA-rggq-f2wf-m6cp
CRITICALAll versions of jajajejejiji typosquatted a popular package of similar name and tracked users who had installed the incorrect package. The package uploaded information to a remote server including: name of the downloaded package, name of the intended package, the Node version and whether the process was running as sudo. There is no further compromise.
- Affected
- >= 0
- Fixed in
- not stated
- Weakness
- CWE-506
- Published
- 2020-09-02
- Source
- github