Description
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/519
Related Vulnerabilities
CVE-2022-31150 Vulnerability in maven package org.webjars.npm:undici
CVE-2017-7660 Vulnerability in maven package org.apache.solr:solr-core
CVE-2016-4999 Vulnerability in maven package org.dashbuilder:dashbuilder-dataset-sql
CVE-2021-29459 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web
CVE-2022-28820 Vulnerability in maven package com.adobe.acs:acs-aem-commons