PT-2020-20972 · Package · Package
Published
2020-09-03
·
Updated
2020-09-03
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Package version 2.0.2
Description
The issue involves malicious code in the package that targets the Ethereum cryptocurrency, allowing it to perform unauthorized transactions to wallets not controlled by the user.
Recommendations
Remove the package from your environment to prevent further unauthorized transactions. Additionally, ensure that no Ethereum funds were compromised as a result of this issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Package