Description
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
Remediation
References
https://nodesecurity.io/advisories/481
Related Vulnerabilities
CVE-2023-35141 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2021-23702 Vulnerability in npm package object-extend
CVE-2020-2181 Vulnerability in maven package org.jenkins-ci.plugins:credentials-binding
CVE-2017-1000048 Vulnerability in maven package org.webjars.bower:qs
CVE-2018-20822 Vulnerability in maven package org.webjars.npm:node-sass