{"id":"GHSA-38hx-3542-8fh3","aliases":[],"url":"https://o3.security/vulnerability/GHSA-38hx-3542-8fh3","summary":"Malicious code in `electorn`","details":"npm packages `loadyaml` and `electorn` were removed from the npm registry for containing malicious code. Upon installation the package runs a preinstall script that writes a public comment on GitHub containing the following information:\n- IP and IP-based geolocation\n- home directory name\n- local username \n\nThe malicious packages have been removed from the npm registry and the leaked content removed from GitHub.","published":"2020-10-01T17:09:56Z","modified":"2020-10-01T17:09:44Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"electorn","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1562"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-10-01T17:09:44Z"}}