GHSA-4964-cjrr-jg97
CRITICALVersion 3.3.1 of jqeury contains malicious code as a preinstall script. The package is malware designed to take advantage of users making a mistake when typing the name of a module to install. When installed, the package downloads a file from a remote server, executes it and opened a backdoor.
- Affected
- >= 0
- Fixed in
- not stated
- Weakness
- CWE-506
- Published
- 2020-09-02
- Source
- github