{"id":"GHSA-8mm3-2mcj-cx6r","aliases":[],"url":"https://o3.security/vulnerability/GHSA-8mm3-2mcj-cx6r","summary":"Malicious Package in angluar-cli","details":"Version 0.0.3 of `angluar-cli` contains malicious code as a postinstall script. The package is malware designed to take advantage of users making a mistake when typing the name of a module to install. When installed the package attempts to remove files and stop processes related to McAfee antivirus on macOS.\n\n\n## Recommendation\n\nRemove the package from your environment and verify whether files were deleted and if processes were stopped.","published":"2020-09-11T21:09:24Z","modified":"2021-09-30T21:57:57Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"angluar-cli","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/918"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-30T21:57:57Z"}}