Description
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Remediation
References
https://nodesecurity.io/advisories/519
Related Vulnerabilities
CVE-2020-8910 Vulnerability in maven package org.webjars.npm:google-closure-library
CVE-2014-3623 Vulnerability in maven package org.apache.wss4j:wss4j
CVE-2022-45384 Vulnerability in maven package org.jenkins-ci.plugins:reverse-proxy-auth-plugin
CVE-2014-3120 Vulnerability in maven package org.elasticsearch:elasticsearch