Description
mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/485
Related Vulnerabilities
CVE-2023-26107 Vulnerability in npm package sketchsvg
CVE-2016-6796 Vulnerability in maven package org.apache.tomcat:tomcat-jasper
CVE-2022-29599 Vulnerability in maven package org.apache.maven.shared:maven-shared-utils
CVE-2022-3145 Vulnerability in npm package @okta/oidc-middleware
CVE-2021-21172 Vulnerability in maven package org.webjars.npm:electron