PT-2020-21537 · Unknown · Destroyer-Of-Worlds

Published

2020-09-02

·

Updated

2020-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions destroyer-of-worlds (affected versions not specified)
Description The issue concerns a package that contains malicious code, specifically a bash script run as a postinstall script. This script is designed to delete system files and exhaust system resources by creating a large file, initiating a fork bomb, and executing an endless loop. The malicious code targets UNIX systems.
Recommendations Remove the destroyer-of-worlds package from your environment and perform additional incident response on your system's files and processes.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-W3F3-4J22-2V3P

Affected Products

Destroyer-Of-Worlds