Description
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/517
Related Vulnerabilities
CVE-2014-10066 Vulnerability in npm package fancy-server
CVE-2021-46366 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2020-9480 Vulnerability in maven package org.apache.spark:spark-network-shuffle_2.11
CVE-2019-18818 Vulnerability in npm package strapi
CVE-2020-2260 Vulnerability in maven package org.jenkins-ci.plugins:perfecto