PT-2020-21169 · Angular · Angular-Cli
Published
2020-09-11
·
Updated
2020-09-11
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
angular-cli version 0.0.3
Description
The issue concerns malicious code in a postinstall script. This malware is designed to exploit typing mistakes when installing modules, targeting macOS users. Upon installation, it attempts to remove files and stop processes related to McAfee antivirus.
Recommendations
Remove the package from your environment and verify whether files were deleted and if processes were stopped.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Angular-Cli