CVE-2022-23812: Embedded Malicious Code in node-ipc
(updated )
This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets users with IP located in Russia or Belarus, and overwrites their files with a heart emoji.
References
- github.com/RIAEvangelist/node-ipc/blob/847047cf7f81ab08352038b2204f0e7633449580/dao/ssl-geospec.js
- github.com/RIAEvangelist/node-ipc/commit/847047cf7f81ab08352038b2204f0e7633449580
- github.com/RIAEvangelist/node-ipc/issues/233
- github.com/RIAEvangelist/node-ipc/issues/236
- github.com/advisories/GHSA-97m3-w2cp-4xx6
- nvd.nist.gov/vuln/detail/CVE-2022-23812
- snyk.io/vuln/SNYK-JS-NODEIPC-2426370
Detect and mitigate CVE-2022-23812 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →