Security Advisory

CVE-2019-19771

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-12-12 19:49:40
Last updated 2024-08-05 02:25:12
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.