Description
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Remediation
References
https://nodesecurity.io/advisories/543
Related Vulnerabilities
CVE-2019-10798 Vulnerability in npm package rdf-graph-array
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.freemarker
CVE-2017-4974 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2017-9735 Vulnerability in maven package org.eclipse.jetty:jetty-util
CVE-2021-23337 Vulnerability in maven package org.webjars:lodash