Description
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/508
Related Vulnerabilities
CVE-2022-38369 Vulnerability in maven package org.apache.iotdb:iotdb-server
CVE-2023-5104 Vulnerability in npm package nocodb
CVE-2019-10382 Vulnerability in maven package org.jenkins-ci.plugins:labmanager
CVE-2018-6874 Vulnerability in npm package auth0-lock
CVE-2018-8013 Vulnerability in maven package org.apache.xmlgraphics:batik-dom