{"id":"GHSA-j8qr-rvcv-crhv","summary":"Malicious Package in electron-native-notify","details":"All versions of `electron-native-notify` contain malicious code. The package was part of a targeted attack to steal cryptocurrency wallet seeds and upload them to a remote server, effectively giving attackers access to users wallets.\n\n\n## Recommendation\n\nRemove the package from your environment and [follow the recommendations by Komodo](https://komodoplatform.com/vulnerability-discovered-in-komodos-agama-wallet-this-is-what-you-need-to-do/)","modified":"2020-08-31T18:40:50Z","published":"2020-09-11T21:18:05Z","database_specific":{"cwe_ids":[],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-08-31T18:40:50Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://blog.npmjs.org/post/185397814280/plot-to-steal-cryptocurrency-foiled-by-the-npm"},{"type":"WEB","url":"https://komodoplatform.com/vulnerability-discovered-in-komodos-agama-wallet-this-is-what-you-need-to-do"},{"type":"WEB","url":"https://www.npmjs.com/advisories/927"}],"affected":[{"package":{"name":"electron-native-notify","ecosystem":"npm","purl":"pkg:npm/electron-native-notify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-j8qr-rvcv-crhv/GHSA-j8qr-rvcv-crhv.json"}}],"schema_version":"1.9.0"}