MAL-2023-1551
Dashboard / Malicious Package / MAL-2023-1551
MAL-2023-1551
Summary: Malicious code in coingecko-price (npm)
Details: Source: checkmarx (06ba52961b5d886349fdb5a7c3e6362cedaaa64cb5857d5645d7360a68d133d1) Lazarus Group targeting blockchain and cryptocurrency companies by exploiting software supply chains through malicious npm packages and social engineering tactics
References: https://medium.com/checkmarx-security/lazarus-group-launches-first-open-source-supply-chain-attacks-targeting-crypto-sector-cabc626e404e, https://security.snyk.io/vuln/SNYK-JS-COINGECKOPRICE-5819588
Affected packages
Package
Name: coingecko-price
Purl: pkg:npm/coingecko-price
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
Affected versions
3.2.12
3.2.13
