Description
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Remediation
References
https://nodesecurity.io/advisories/542
Related Vulnerabilities
CVE-2020-4038 Vulnerability in maven package org.webjars.npm:graphql-playground-html
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat:el-api
CVE-2021-46361 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2019-13990 Vulnerability in maven package org.quartz-scheduler:quartz
CVE-2018-20318 Vulnerability in maven package com.github.binarywang:weixin-java-common