PT-2020-21169 · Angular · Angular-Cli

Published

2020-09-11

·

Updated

2020-09-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions angular-cli version 0.0.3
Description The issue concerns malicious code in a postinstall script. This malware is designed to exploit typing mistakes when installing modules, targeting macOS users. Upon installation, it attempts to remove files and stop processes related to McAfee antivirus.
Recommendations Remove the package from your environment and verify whether files were deleted and if processes were stopped.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-8MM3-2MCJ-CX6R

Affected Products

Angular-Cli