Malicious code in `electorn`
Critical severity
GitHub Reviewed
Published
Oct 1, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Oct 1, 2020
Published to the GitHub Advisory Database
Oct 1, 2020
Last updated
Jan 9, 2023
npm packages
loadyaml
andelectorn
were removed from the npm registry for containing malicious code. Upon installation the package runs a preinstall script that writes a public comment on GitHub containing the following information:The malicious packages have been removed from the npm registry and the leaked content removed from GitHub.
References