Description
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/519
Related Vulnerabilities
CVE-2018-1000644 Vulnerability in maven package org.eclipse.rdf4j:rdf4j-rio-rdfxml
CVE-2019-20444 Vulnerability in maven package io.netty:netty-codec-http
CVE-2022-24913 Vulnerability in maven package com.fasterxml.util:java-merge-sort
CVE-2018-3718 Vulnerability in npm package serve
CVE-2020-17518 Vulnerability in maven package org.apache.flink:flink-runtime_2.11