Description
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/509
Related Vulnerabilities
CVE-2020-2221 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2017-3523 Vulnerability in maven package mysql:mysql-connector-java
CVE-2016-6812 Vulnerability in maven package org.apache.cxf:cxf-rt-transports-http
CVE-2022-45146 Vulnerability in maven package org.bouncycastle:bc-fips
CVE-2020-35451 Vulnerability in maven package org.apache.oozie:oozie-tools