Description
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
Remediation
References
https://nodesecurity.io/advisories/481
Related Vulnerabilities
CVE-2019-5448 Vulnerability in npm package yarn
CVE-2021-23341 Vulnerability in maven package org.webjars.npm:prismjs
CVE-2021-4307 Vulnerability in maven package org.webjars.bower:baobab
CVE-2021-21120 Vulnerability in npm package electron
CVE-2021-43090 Vulnerability in maven package com.predic8:soa-model-core