icon

We found results for “

MSC-2023-12502

Date: May 19, 2023

This package has been identified by Mend as containing potential malicious functionality. The severity of the functionality can change depending on where the library is running (user's machine or backend server). The following risks were identified: Malware dropper – this package contains a Trojan horse, allowing the unauthorized installation of other potentially malicious software. Exfiltrating sensitive private user information – unauthorized access to sensitive system information, such as browser data, application tokens, etc. Suspect publisher – this publisher has a history of delivering packages previously flagged as malicious.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Embedded Malicious Code

CWE-506

CVSS v3

Base Score:
Attack Vector (AV):
Attack Complexity (AC):
Privileges Required (PR):
User Interaction (UI):
Scope (S):
Confidentiality (C): PARTIAL
Integrity (I): PARTIAL
Availability (A): PARTIAL

Do you need more information?

Contact Us