Description
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/501
Related Vulnerabilities
CVE-2017-3151 Vulnerability in maven package org.apache.atlas:apache-atlas
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-master
CVE-2017-16010 Vulnerability in maven package org.webjars.bower:i18next
CVE-2017-16121 Vulnerability in npm package datachannel-client
CVE-2022-36083 Vulnerability in maven package org.webjars.npm:jose