OSV 1.4.0 · github-reviewed · 修改于 2021-10-01 04:05
发布时间
2020-09-04 02:19
GitHub 审查时间
2020-09-01 02:46
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-jxf5-7x3j-8j9m/GHSA-jxf5-7x3j-8j9m.json
Version 3.0.2 of load-from-cwd-or-npm contains malicious code. The malware breaks functionality of the purescript-installer package by injecting targeted code.
Upgrade to version 3.0.4 or later. There is no indication of further compromise.
3.0.2