Description
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
Remediation
References
https://nodesecurity.io/advisories/481
Related Vulnerabilities
CVE-2022-4725 Vulnerability in maven package com.amazonaws:aws-android-sdk-core
CVE-2017-1000190 Vulnerability in maven package org.simpleframework:simple-xml
CVE-2021-4329 Vulnerability in maven package org.webjars.npm:json-logic-js
CVE-2023-26149 Vulnerability in maven package org.webjars.npm:quill-mention
CVE-2016-0785 Vulnerability in maven package org.apache.struts.xwork:xwork-core