{"id":"GHSA-j8qr-rvcv-crhv","aliases":[],"url":"https://o3.security/vulnerability/GHSA-j8qr-rvcv-crhv","summary":"Malicious Package in electron-native-notify","details":"All versions of `electron-native-notify` contain malicious code. The package was part of a targeted attack to steal cryptocurrency wallet seeds and upload them to a remote server, effectively giving attackers access to users wallets.\n\n\n## Recommendation\n\nRemove the package from your environment and [follow the recommendations by Komodo](https://komodoplatform.com/vulnerability-discovered-in-komodos-agama-wallet-this-is-what-you-need-to-do/)","published":"2020-09-11T21:18:05Z","modified":"2020-08-31T18:40:50Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"electron-native-notify","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://blog.npmjs.org/post/185397814280/plot-to-steal-cryptocurrency-foiled-by-the-npm"},{"type":"WEB","url":"https://komodoplatform.com/vulnerability-discovered-in-komodos-agama-wallet-this-is-what-you-need-to-do"},{"type":"WEB","url":"https://www.npmjs.com/advisories/927"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:40:50Z"}}