{"id":"GHSA-7cgc-fjv4-52x6","summary":"Malware in pre-build binaries of bignum","details":"### Impact\n\nbignum releases from v0.12.2 to v0.13.0 (inclusive) used node-pre-gyp to optionally download pre-built binary versions of the addon. These binaries were published on a now-expired S3 bucket which has since been claimed by a malicious third party which is now serving binaries containing malware that exfiltrates data from the user's computer.\n\n### Patches\n\nv0.13.1 does not use node-pre-gyp and does not have support for downloading pre-built binaries in any form, avoiding the risk of malicious downloads.","modified":"2023-05-24T16:43:58Z","published":"2023-05-24T16:43:58Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-506"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-05-24T16:43:58Z"},"references":[{"type":"WEB","url":"https://github.com/justmoon/node-bignum/security/advisories/GHSA-7cgc-fjv4-52x6"},{"type":"WEB","url":"https://github.com/justmoon/node-bignum/commit/57e48c3f052249725517415d83c7147e4a8c44c8"},{"type":"WEB","url":"https://github.com/justmoon/node-bignum/commit/72951c53e7c5c1ac157f04686dc12c3c393b4b08"},{"type":"PACKAGE","url":"https://github.com/justmoon/node-bignum"}],"affected":[{"package":{"name":"bignum","ecosystem":"npm","purl":"pkg:npm/bignum"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.12.2"},{"fixed":"0.13.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-7cgc-fjv4-52x6/GHSA-7cgc-fjv4-52x6.json"}}],"schema_version":"1.9.0"}