Description
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/510
Related Vulnerabilities
CVE-2018-21234 Vulnerability in maven package org.jodd:jodd-json
CVE-2020-7961 Vulnerability in maven package com.liferay.portal:portal-impl
CVE-2019-19771 Vulnerability in npm package bitcionjslib
CVE-2019-10750 Vulnerability in npm package deeply
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-logparser