Malicious Package in boogeyman
Critical severity
GitHub Reviewed
Published
Sep 1, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 1, 2020
Last updated
Jan 9, 2023
All versions of
boogeyman
are considered malicious. This particular package would download a payload from pastebin.com, eval it to read ssh keys and the users.npmrc
and send them to a private pastebin account.Recommendation
This package was published to the npm Registry for a very short period of time. If you happen to find it in your environment you should revoke and rotate your ssh keys and your npm token.
References