Description
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/501
Related Vulnerabilities
CVE-2021-27906 Vulnerability in maven package org.apache.pdfbox:pdfbox
CVE-2019-0199 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2018-19057 Vulnerability in npm package simplemde
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-mysql-cdc
CVE-2019-10395 Vulnerability in maven package org.jenkins-ci.plugins:build-environment