Description
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/480
Related Vulnerabilities
CVE-2022-29256 Vulnerability in npm package sharp
CVE-2020-2296 Vulnerability in maven package org.jenkins-ci.plugins:shared-objects
CVE-2020-6858 Vulnerability in maven package com.hotels.styx:styx-api
CVE-2019-1003062 Vulnerability in maven package org.jenkins-ci.plugins:aws-cloudwatch-logs-publisher