Description
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Remediation
References
https://nodesecurity.io/advisories/541
Related Vulnerabilities
CVE-2018-1336 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2018-3739 Vulnerability in maven package org.webjars.npm:https-proxy-agent
CVE-2017-9802 Vulnerability in maven package org.apache.sling:org.apache.sling.servlets.post
CVE-2020-28847 Vulnerability in npm package valine
CVE-2021-21641 Vulnerability in maven package org.jenkins-ci.plugins:promoted-builds