Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade bignum
to version 0.13.1 or higher.
bignum is a malicious package.
The affected package versions are using node-pre-gyp
to optionally download pre-built binary versions of the addon. These binaries were published on a now-expired S3 bucket which has since been claimed by a malicious third party which is now serving binaries containing malware that exfiltrates data from the user's computer.
Note:
Only versions v0.12.2 to v0.13.0 of this package contain malware. Users can continue using non-impacted versions.
v0.13.1 does not use node-pre-gyp
and does not have support for downloading pre-built binaries in any form, avoiding the risk of malicious downloads.