PT-2020-21565 · Axios · Axios

Published

2020-09-01

·

Updated

2020-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions axois (affected versions not specified)
Description The issue concerns a malicious package designed to exploit users who mistakenly install it due to a typo in the module name. Upon execution, the package communicates with a Command and Control server to execute arbitrary commands.
Recommendations Revoke and rotate all credentials found on the compromised machine. Completely erase the affected machine and reinstall the Operating System.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-WPFC-3W63-G4HM

Affected Products

Axios