Description
The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Remediation
References
https://nodesecurity.io/advisories/540
Related Vulnerabilities
CVE-2018-1288 Vulnerability in maven package org.apache.kafka:kafka_2.11
CVE-2021-23377 Vulnerability in npm package onion-oled-js
CVE-2020-7771 Vulnerability in npm package asciitable.js
CVE-2021-23448 Vulnerability in npm package config-handler
CVE-2015-0254 Vulnerability in maven package org.apache.taglibs:taglibs-standard