GHSA-4jfq-q299-g4cr
UNKNOWNAll versions of reqquest typosquatted a popular package of similar name and tracked users who had installed the incorrect package. The package uploaded information to a remote server including: name of the downloaded package, name of the intended package, the Node version and whether the process was running as sudo. There is no further compromise.
- Affected
- >=0
- Fixed in
- not stated
- Weakness
- CWE-506
- Published
- 2020-09-02
- Source
- osv