Description
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Remediation
References
https://nodesecurity.io/advisories/544
Related Vulnerabilities
CVE-2017-16138 Vulnerability in maven package org.webjars:mime
CVE-2023-41034 Vulnerability in maven package org.eclipse.leshan:leshan-core
CVE-2020-15087 Vulnerability in maven package io.prestosql:presto-main
CVE-2022-2466 Vulnerability in maven package io.quarkus:quarkus-smallrye-graphql
CVE-2022-43414 Vulnerability in maven package org.jenkins-ci.plugins:nunit