0.0.1-security
7 days ago
7 days ago
Known vulnerabilities in the node-orm-mongoose package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
node-orm-mongoose is a malicious package. This is a "typosquatting" package, which means the package name is based on existing repositories, namespaces, or components, it aims to trick users to download the package which contains a malicious code. This package contains a hex-encoded loader which upon installation collects host metadata, decodes its follow-on script and fetches second-stage malware. How to fix Malicious Package? Avoid using all malicious instances of the | * |