MAL-2024-9424
Dashboard / Malicious Package / MAL-2024-9424
MAL-2024-9424
Published: 17 Oct 2024Last Modified: 17 Oct 2024
Summary: Malicious code in ethers-mew (npm)
Details: The package contains additional code to append a hardcoded SSH key to the user's authorized_keys file, creating a backoor, along with exfiltrating user private keys to an attack-controlled server.
References:
Affected packages
Package
Name: ethers-mew
Purl: pkg:npm/ethers-mew
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
6.13.4
