OSV 1.4.0 · github-reviewed · 修改于 2021-10-01 21:28
发布时间
2020-09-02 05:07
GitHub 审查时间
2020-09-01 02:32
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-9hc2-w9gg-q6jw/GHSA-9hc2-w9gg-q6jw.json
All versions of boogeyman are considered malicious. This particular package would download a payload from pastebin.com, eval it to read ssh keys and the users .npmrc and send them to a private pastebin account.
This package was published to the npm Registry for a very short period of time. If you happen to find it in your environment you should revoke and rotate your ssh keys and your npm token.