Malicious Package Affecting flybook-table package, versions *


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Mature

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-FLYBOOKTABLE-8536903
  • published19 Dec 2024
  • disclosed19 Dec 2024
  • creditPaul McCarty

Introduced: 19 Dec 2024

New Malicious CVE-2024-54790  (opens in a new tab)
CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the flybook-table package.

Overview

flybook-table is a malicious package. This package contains malicious code that relates to MacOS malware. The code is attempting to steal session credentials from hundreds of websites, browser cache, cookies, local storage, iCloud accounts, browser plugins, and other places that store credentials.

References

CVSS Scores

version 4.0
version 3.1