{"id":"GHSA-vv52-3mrp-455m","aliases":[],"url":"https://o3.security/vulnerability/GHSA-vv52-3mrp-455m","summary":"Malicious Package in m-backdoor","details":"All versions of `m-backdoor` contain malicious code. The package downloads a file from a remote server and executes it as a preinstall script. At the time of the release of this advisory the downloaded file only defaces websites by removing elements randomly from the DOM. \n\n\n## Recommendation\n\nRemove the package from your system.","published":"2020-09-03T15:53:36Z","modified":"2020-08-31T19:01:56Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"m-backdoor","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1513"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T19:01:56Z"}}