PT-2019-15949 · Lodash+1 · Lodash+1

Published

2019-12-12

·

Updated

2021-07-21

·

CVE-2019-19771

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions lodahs package versions 0.0.1
Description The lodahs package is a Trojan horse that may have been installed due to a typo of the lodash package name. It is designed to find and exfiltrate cryptocurrency wallets, potentially compromising the security of the affected system. All versions of this package contain malware. Any computer with this package installed should be considered fully compromised.
Recommendations For lodahs package version 0.0.1, remove the package immediately. However, due to the potential for full control of the computer to have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software. Additionally, all secrets and keys stored on the compromised computer should be rotated immediately from a different computer.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19771
GHSA-HM6Q-R2JC-CPQH

Affected Products

Lodahs
Lodash