Description
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/501
Related Vulnerabilities
CVE-2021-4040 Vulnerability in maven package org.apache.activemq:artemis-commons
CVE-2020-2256 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-maven-parent
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.components:codemirror
CVE-2023-22665 Vulnerability in maven package org.apache.jena:jena-arq