GHSA-33gc-f8v9-v8hm – ladder-text-js
Package
Manager: npm
Name: ladder-text-js
Vulnerable Version: <0
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: N/A
EPSS: N/A pctlN/A
Details
Malicious Package in ladder-text-js `ladder-text-js` contained a malicious script that attempted to delete all files when `npm test` was run. ## Recommendation This module has been unpublished from the npm Registry. If you find this module in your environment remove it.
Metadata
Created: 2020-09-01T20:41:40Z
Modified: 2021-10-01T13:27:36Z
Source: MANUAL
CWE IDs: ["CWE-506"]
Alternative ID: N/A
Finding: N/A
Auto approve: 0