CVE-2019-19771

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/12/2019
Last modified:
21/07/2021

Description

The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lodahs_project:lodahs:1.0.0:*:*:*:*:node.js:*:*