We found results for “”
MSC-2025-5430
Date: May 11, 2025
This package version was compromised to include a RAT(Remote-access-trojan), when installed the attacker is able to send remote commands to the compromised machine. As this package is no longer maintained, we recommend returning to the latest safe version 2.0.82 or 1.0.109. For more details -> https://www.bleepingcomputer.com/news/security/supply-chain-attack-hits-npm-package-with-45-000-weekly-downloads/
Language: JS
Severity Score
Severity Score
Weakness Type (CWE)
Hidden Functionality
CWE-912CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


