Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6709
HistoryJun 08, 2018 - 2:14 a.m.

Malicious Typo-Squatting

2018-06-0802:14:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.002 Low

EPSS

Percentile

53.8%

coffe-script is a maliciously typo-squatting package. During the installation of these packages, the user’s private SSH key and bash history are set to a third party server.

CPENameOperatorVersion
coffe-scriptle1.0.1

0.002 Low

EPSS

Percentile

53.8%