Description
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/497
Related Vulnerabilities
CVE-2016-10684 Vulnerability in npm package healthcenter
CVE-2020-4051 Vulnerability in maven package org.webjars.npm:dijit
CVE-2017-12616 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2020-2185 Vulnerability in maven package org.jenkins-ci.plugins:ec2
CVE-2021-29943 Vulnerability in maven package org.apache.solr:solr-core