Malicious Package in eslint-config-airbnb-standard
Critical severity
GitHub Reviewed
Published
Sep 1, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 1, 2020
Last updated
Jan 9, 2023
Version 2.0.0 of
eslint-config-airbnb-standard
was published with a bundled version ofeslint-scope
that was found to contain malicious code. This code would read the users.npmrc
file and send it's contents to a remote server.Recommendation
The best course of action if you found this package installed in your environment is to revoke all your npm tokens and use a different version of the module. You can find instructions on how to do that here. https://docs.npmjs.com/getting-started/working_with_tokens#how-to-revoke-tokens
References