OSV 1.4.0 · github-reviewed · 修改于 2021-10-01 21:30
发布时间
2020-09-02 05:21
GitHub 审查时间
2020-09-01 02:33
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-9x64-5r7x-2q53/GHSA-9x64-5r7x-2q53.json
Version 0.1.1 of flatmap-stream is considered malicious.
This module runs an encrypted payload targeting a very specific application, copay and because they shared the same description it would have likely worked for copay-dash.
The injected code:
The decrypted data was part of a module, which was then compiled in memory and executed.
This module performed the following actions:
The chunk of code that was written out was the actual malicious code, intended to be run on devices owned by the end users of Copay.
This code would do the following:
If you find this module in your environment it's best to remove it. The malicious version of event-stream and flatmap-stream have been removed from the npm Registry.
0.1.1