Description
The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Remediation
References
https://nodesecurity.io/advisories/540
Related Vulnerabilities
CVE-2021-30109 Vulnerability in npm package froala-editor
CVE-2019-10773 Vulnerability in npm package @pnpm/package-bins
CVE-2020-7680 Vulnerability in npm package docsify
CVE-2022-35915 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts
CVE-2018-7489 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind