Description
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/507
Related Vulnerabilities
CVE-2022-28820 Vulnerability in maven package com.adobe.acs:acs-aem-commons-ui.apps
CVE-2020-2296 Vulnerability in maven package org.jenkins-ci.plugins:shared-objects
CVE-2016-6810 Vulnerability in maven package org.apache.activemq:activemq-web-console
CVE-2022-24289 Vulnerability in maven package org.apache.cayenne:cayenne-server