CWE-506
99 CVEs • Abstraction: Class
Embedded Malicious Code
The product contains code that appears to be malicious in nature.
CVEs (99)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Npm Script Demo Project 1Npm Script Demo Nov 21, 2024 Jun 7, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry. |
1Cross Env.js Project 1Cross Env.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Shadowsock Project 1Shadowsock Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Http Proxy.js Project 1Http Proxy.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Noderequest Project 1Noderequest Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Nodemailer.js Project 1Nodemailer.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Nodemailer Js Project 1Nodemailer Js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Nodeffmpeg Project 1Nodeffmpeg Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Node Opencv Project 1Node Opencv Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Openssl.js Project 1Openssl.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Node Openssl Project 1Node Openssl Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Node Opensl Project 1Node Opensl Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |