Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the pretty_color
package.
pretty_color is a malicious package.
Within version.rb
, obfuscated code can be found which, on Windows systems, generates and runs a malicious VBScript the_Score.vbs
. This script will:
%PROGRAMDATA%\Microsoft Essentials\Software Essentials.vbs
the_Score.vbs
also adds the path of the newly dropped Software Essentials.vbs to the appropriate Windows registry key, to make the malware run every time the system boots.