{"id":"GHSA-x48m-gp6r-gp4v","aliases":[],"url":"https://o3.security/vulnerability/GHSA-x48m-gp6r-gp4v","summary":"Malicious Package in rate-map","details":"Version 1.0.3 of `rate-map`  contains malicious code. The malware breaks functionality of the `purescript-installer` package by rewriting code of the `dl-tar` dependency.\n\n\n## Recommendation\n\nUpgrade to version 1.0.5 or later. There is no indication of further compromise.","published":"2020-09-03T18:21:26Z","modified":"2021-09-30T20:04:54Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"rate-map","fixedVersion":"1.0.5"}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1083"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-30T20:04:54Z"}}