cookie-parser-legacy@0.0.1-security

security holding package

Direct Vulnerabilities

Known vulnerabilities in the cookie-parser-legacy package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Malicious Package

cookie-parser-legacy is a malicious package. This package contains malicious code that uses another malicious package moustick (Snyk Advisory) as a dependency to fetch a remote payload from attacker-controlled URL (https://www.jsonkeeper.com/b/MYUKZ). The payload is designed to extract RELAYER_PRIVATE_KEY and JWT_SECRET from the victim's .env file. While this package attempting to impersonate a valid pakage cookie-parser by using the real author name (TJ Holowaychuk) and points to the legitimate expressjs/cookie-parser GitHub repo, there is no connection between that organization and this package authorship. Its content was not removed from the official package manager yet.

How to fix Malicious Package?

Avoid using all malicious instances of the cookie-parser-legacy package.

*