VDB
KO
CRITICAL 9.8

GHSA-97m3-w2cp-4xx6

Embedded Malicious Code in node-ipc

Details

The package node-ipc versions 10.1.1 and 10.1.2 are vulnerable to embedded malicious code that was introduced by the maintainer. The malicious code was intended to overwrite arbitrary files dependent upon the geo-location of the user IP address. The maintainer removed the malicious code in version 10.1.3.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / node-ipc
Introduced in: 10.1.1 Fixed in: 10.1.3
Fix npm install node-ipc@10.1.3

References