Description
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/501
Related Vulnerabilities
CVE-2017-9802 Vulnerability in maven package org.apache.sling:org.apache.sling.servlets.post
CVE-2021-33587 Vulnerability in npm package css-what
CVE-2016-5394 Vulnerability in maven package org.apache.sling:org.apache.sling.xss
CVE-2019-16303 Vulnerability in npm package generator-jhipster-kotlin
CVE-2023-39022 Vulnerability in maven package opensymphony:oscore