Description
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/517
Related Vulnerabilities
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-support-oidc
CVE-2014-10064 Vulnerability in npm package qs
CVE-2018-12540 Vulnerability in maven package io.vertx:vertx-web
CVE-2017-12631 Vulnerability in maven package org.apache.cxf.fediz:fediz-spring3
CVE-2019-17570 Vulnerability in maven package org.apache.xmlrpc:xmlrpc-client