node-orm-mongoose@0.0.1-security

security holding package

Direct Vulnerabilities

Known vulnerabilities in the node-orm-mongoose package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Malicious Package

node-orm-mongoose is a malicious package. This is a "typosquatting" package, which means the package name is based on existing repositories, namespaces, or components, it aims to trick users to download the package which contains a malicious code.

This package contains a hex-encoded loader which upon installation collects host metadata, decodes its follow-on script and fetches second-stage malware.

How to fix Malicious Package?

Avoid using all malicious instances of the node-orm-mongoose package.

*