moustick@0.0.1-security

security holding package

Direct Vulnerabilities

Known vulnerabilities in the moustick package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Malicious Package

moustick is a malicious package. This package contains malicious code that fetches and eval() a remote payload from attacker-controlled URL (https://www.jsonkeeper.com/b/MYUKZ) on require() in moustick/index.js. The payload is designed to extract RELAYER_PRIVATE_KEY and JWT_SECRET from the victim's .env file. While this package attempting to impersonate a valid pakage cookie-signature by using the real author name (TJ Holowaychuk) and points to the legitimate visionmedia/node-cookie-signature GitHub repo, there is no connection between that organization and this package authorship. Its content was not removed from the official package manager yet.

How to fix Malicious Package?

Avoid using all malicious instances of the moustick package.

*