Description
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/508
Related Vulnerabilities
CVE-2019-10476 Vulnerability in maven package org.jenkins-ci.plugins:zulip
CVE-2017-4947 Vulnerability in maven package com.vmware.xenon:xenon-common
CVE-2019-10389 Vulnerability in maven package org.jenkins-ci.plugins:relution-publisher
CVE-2022-41932 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-39368 Vulnerability in maven package org.eclipse.californium:scandium