{"id":"GHSA-wxrm-2h86-v95f","aliases":[],"url":"https://o3.security/vulnerability/GHSA-wxrm-2h86-v95f","summary":"Malicious Package in pizza-pasta","details":"Version 1.0.3 of `pizza-pasta` contains malicious code as a install scripts. The package created folders in the system's Desktop and downloaded an image from `imgur.com`. The package also printed the users SSH keys to the console.\n\n\n## Recommendation\n\nRemove the package from your environment. There are no evidences of further compromise.","published":"2020-09-03T21:04:20Z","modified":"2021-09-29T20:45:26Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"pizza-pasta","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1196"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-29T20:45:26Z"}}