Malicious Package Affecting destroyer-of-worlds package, versions *
Threat Intelligence
Exploit Maturity
Mature
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-DESTROYEROFWORLDS-174777
- published 23 May 2019
- disclosed 22 May 2019
- credit Adam Baldwin
How to fix?
Avoid using destroyer-of-worlds
altogether.
Overview
destroyer-of-worlds is a malicious package.
The package contains a bash script that runs as a post-install script. The script delete system files and attempt to exhaust resources by creating a large file, a fork bomb and an endless loop. The script targets UNIX systems.
References
CVSS Scores
version 3.1