Description
node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/502
Related Vulnerabilities
CVE-2020-2146 Vulnerability in maven package fr.edf.jenkins.plugins:mac
CVE-2020-7743 Vulnerability in maven package org.webjars.bower:mathjs
CVE-2018-16475 Vulnerability in npm package knightjs
CVE-2023-33246 Vulnerability in maven package org.apache.rocketmq:rocketmq-broker
CVE-2020-2207 Vulnerability in maven package org.jenkins-ci.plugins:vncviewer