Malicious Package

Affecting eslint-scope package, versions =3.7.2

high severity

Overview

eslint-scope is the ECMAScript scope analyzer used in ESLint.

Version 3.7.2 was identified as malicious after a possible npm account takeover. During installation, the malicious code download code from pastebin.com, then executed it. It sent the contents of the user’s .npmrc file to the attacker, which typically contains access tokens for publishing to npm.

The malicious package versions have been unpublished from npm.

Remediation

Do not use version 3.7.2 of eslint-scope.

References

Do your applications use this vulnerable package?

Credit
Unknown
CWE
CWE-506
Snyk ID
npm:eslint-scope:20180712
Disclosed
12 Jul, 2018
Published
12 Jul, 2018