OSV 1.4.0 · github-reviewed · 修改于 2021-10-01 21:27
发布时间
2020-09-02 04:47
GitHub 审查时间
2020-09-01 02:32
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-m852-866j-69j8/GHSA-m852-866j-69j8.json
Version 2.0.0 of eslint-config-airbnb-standard was published with a bundled version of eslint-scope that was found to contain malicious code. This code would read the users .npmrc file and send it's contents to a remote server.
The best course of action if you found this package installed in your environment is to revoke all your npm tokens and use a different version of the module. You can find instructions on how to do that here. https://docs.npmjs.com/getting-started/working_with_tokens#how-to-revoke-tokens
2.0.0