{"id":"GHSA-38hx-3542-8fh3","summary":"Malicious code in `electorn`","details":"npm packages `loadyaml` and `electorn` were removed from the npm registry for containing malicious code. Upon installation the package runs a preinstall script that writes a public comment on GitHub containing the following information:\n- IP and IP-based geolocation\n- home directory name\n- local username \n\nThe malicious packages have been removed from the npm registry and the leaked content removed from GitHub.","modified":"2020-10-01T17:09:44Z","published":"2020-10-01T17:09:56Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-10-01T17:09:44Z","nvd_published_at":null,"cwe_ids":["CWE-506"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1562"}],"affected":[{"package":{"name":"electorn","ecosystem":"npm","purl":"pkg:npm/electorn"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"10.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-38hx-3542-8fh3/GHSA-38hx-3542-8fh3.json"}}],"schema_version":"1.9.0"}