{"id":"GHSA-mfc2-93pr-jf92","summary":"Malicious code in `loadyaml`","details":"npm packages `loadyaml` and `electorn` were removed from the npm registry for containing malicious code. Upon installation the package runs a preinstall script that writes a public comment on GitHub containing the following information:\n- IP and IP-based geolocation\n- home directory name\n- local username \n\nThe malicious packages have been removed from the npm registry and the leaked content removed from GitHub.","modified":"2020-10-01T17:09:29Z","published":"2020-10-01T17:10:15Z","database_specific":{"cwe_ids":["CWE-506"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-10-01T17:09:29Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1563"}],"affected":[{"package":{"name":"loadyaml","ecosystem":"npm","purl":"pkg:npm/loadyaml"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-mfc2-93pr-jf92/GHSA-mfc2-93pr-jf92.json"}}],"schema_version":"1.9.0"}