OSV 1.4.0 · github-reviewed · 修改于 2020-10-02 01:09
发布时间
2020-10-02 01:10
GitHub 审查时间
2020-10-02 01:09
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/10/GHSA-mfc2-93pr-jf92/GHSA-mfc2-93pr-jf92.json
npm packages loadyaml and electorn were removed from the npm registry for containing malicious code. Upon installation the package runs a preinstall script that writes a public comment on GitHub containing the following information:
The malicious packages have been removed from the npm registry and the leaked content removed from GitHub.