{"id":"GHSA-7cgc-fjv4-52x6","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7cgc-fjv4-52x6","summary":"Malware in pre-build binaries of bignum","details":"### Impact\n\nbignum releases from v0.12.2 to v0.13.0 (inclusive) used node-pre-gyp to optionally download pre-built binary versions of the addon. These binaries were published on a now-expired S3 bucket which has since been claimed by a malicious third party which is now serving binaries containing malware that exfiltrates data from the user's computer.\n\n### Patches\n\nv0.13.1 does not use node-pre-gyp and does not have support for downloading pre-built binaries in any form, avoiding the risk of malicious downloads.","published":"2023-05-24T16:43:58Z","modified":"2023-05-24T16:43:58Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"bignum","fixedVersion":"0.13.1"}],"fix":{"url":"https://github.com/justmoon/node-bignum/commit/57e48c3f052249725517415d83c7147e4a8c44c8","label":"justmoon/node-bignum@57e48c3"},"references":[{"type":"WEB","url":"https://github.com/justmoon/node-bignum/security/advisories/GHSA-7cgc-fjv4-52x6"},{"type":"WEB","url":"https://github.com/justmoon/node-bignum/commit/57e48c3f052249725517415d83c7147e4a8c44c8"},{"type":"WEB","url":"https://github.com/justmoon/node-bignum/commit/72951c53e7c5c1ac157f04686dc12c3c393b4b08"},{"type":"PACKAGE","url":"https://github.com/justmoon/node-bignum"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-05-24T16:43:58Z"}}