PT-2019-15949 · Lodash+1 · Lodash+1
Published
2019-12-12
·
Updated
2021-07-21
·
CVE-2019-19771
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
lodahs package versions 0.0.1
Description
The lodahs package is a Trojan horse that may have been installed due to a typo of the lodash package name. It is designed to find and exfiltrate cryptocurrency wallets, potentially compromising the security of the affected system. All versions of this package contain malware. Any computer with this package installed should be considered fully compromised.
Recommendations
For lodahs package version 0.0.1, remove the package immediately. However, due to the potential for full control of the computer to have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software. Additionally, all secrets and keys stored on the compromised computer should be rotated immediately from a different computer.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lodahs
Lodash