
We found results for “”
WS-2022-0114
Good to know:

Date: April 18, 2022
The package 'epic-ue-loading' in NPM is malicious. The package was uploaded first time in April 18th 2022. All versions are malicious. The malicious package is exfiltrating user information like env variables and sends it out via a pipe-dream webhook. The package seems to target consumers of packages by the user 'spicywombat': https://www.npmjs.com/~spicywombat
Language: JS
Severity Score
Severity Score
Weakness Type (CWE)
Embedded Malicious Code
CWE-506Top Fix

Upgrade Version
No fix version available
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | CHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |