Description
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/484
Related Vulnerabilities
CVE-2018-11041 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-uaa
CVE-2019-10799 Vulnerability in npm package compile-sass
CVE-2022-24827 Vulnerability in maven package com.yahoo.elide:elide-datastore-aggregation
CVE-2018-20595 Vulnerability in maven package org.hswebframework.web:hsweb-system-oauth2-client-web