ZeroHour

CVE-2019-19771

CVSS 3.1
8.8 high
EPSS
1%p68
Published
()
Modified
Description

The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.

Vendors
lodahs project
Products
lodahs
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.