Description
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/500
Related Vulnerabilities
CVE-2012-4431 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2018-1000402 Vulnerability in maven package org.jenkins-ci.plugins:codedeploy
CVE-2023-50422 Vulnerability in maven package com.sap.cloud.security.xsuaa:spring-xsuaa
CVE-2020-2183 Vulnerability in maven package org.jenkins-ci.plugins:copyartifact