Description
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
Remediation
References
https://nodesecurity.io/advisories/481
Related Vulnerabilities
CVE-2021-32850 Vulnerability in npm package @claviska/jquery-minicolors
CVE-2017-12610 Vulnerability in maven package org.apache.kafka:kafka_2.11
CVE-2019-10410 Vulnerability in maven package org.jenkins-ci.plugins:log-parser
CVE-2019-10775 Vulnerability in npm package ecstatic
CVE-2022-2390 Vulnerability in maven package com.google.android.gms:play-services-basement