Description
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/509
Related Vulnerabilities
CVE-2017-4974 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-common
CVE-2020-2123 Vulnerability in maven package org.jenkins-ci.plugins:radargun
CVE-2023-26105 Vulnerability in npm package utilities
CVE-2016-10543 Vulnerability in npm package call
CVE-2018-19413 Vulnerability in maven package org.sonarsource.sonarqube:sonar-plugin-api