Description
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
Remediation
References
https://nodesecurity.io/advisories/542
Related Vulnerabilities
CVE-2017-16215 Vulnerability in npm package sgqserve
CVE-2014-6071 Vulnerability in maven package org.webjars:jquery
CVE-2021-30246 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2019-1003041 Vulnerability in maven package org.jenkins-ci.plugins:groovy
CVE-2017-2585 Vulnerability in maven package org.keycloak:keycloak-server-spi-private