Description
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/514
Related Vulnerabilities
CVE-2022-31186 Vulnerability in npm package next-auth
CVE-2022-24820 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web
CVE-2019-13127 Vulnerability in maven package org.webjars.bowergithub.jgraph:mxgraph
CVE-2018-14732 Vulnerability in maven package org.webjars.npm:webpack-dev-server
CVE-2020-7751 Vulnerability in maven package org.webjars.npm:pathval