Description
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/498
Related Vulnerabilities
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.freemarker
CVE-2022-23712 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-21721 Vulnerability in npm package next
CVE-2017-5648 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2022-41248 Vulnerability in maven package org.jenkins-ci.plugins:bigpanda-jenkins