#VU57962 Embedded malicious code (backdoor) in coa
Published: November 4, 2021
coa
Sergey Berezhnoy
Description
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to presence of embedded malicious functionality in the application code (aka backdoor) that allows a remote attacker to gain unauthorized access to the application.
The npm package has been compromised and includes cryptomining and password stealing malware.