PT-2020-21386 · Npm · Hooka-Tools

Published

2020-09-01

·

Updated

2020-09-01

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions hooka-tools versions (affected versions not specified)
Description The issue concerns compromised and modified versions of hooka-tools that silently run a cryptocoin miner in the background. All affected versions have been removed from the npm registry. However, some versions may still exist in mirrors or caches.
Recommendations Do not install hooka-tools, and remove it if found.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-M36M-X4C5-RJXJ

Affected Products

Hooka-Tools