GHSA-9hc2-w9gg-q6jw – boogeyman
Package
Manager: npm
Name: boogeyman
Vulnerable Version: <0
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: N/A
EPSS: N/A pctlN/A
Details
Malicious Package in boogeyman All versions of `boogeyman` are considered malicious. This particular package would download a payload from pastebin.com, eval it to read ssh keys and the users `.npmrc` and send them to a private pastebin account. ## Recommendation This package was published to the npm Registry for a very short period of time. If you happen to find it in your environment you should revoke and rotate your ssh keys and your npm token.
Metadata
Created: 2020-09-01T21:07:41Z
Modified: 2021-10-01T13:28:13Z
Source: MANUAL
CWE IDs: ["CWE-506"]
Alternative ID: N/A
Finding: N/A
Auto approve: 0