Skip to main content

Embedded Malicious Code in coa

Cxb5dfb167-23a8

  • coa
Severity High
Score 10/10

Summary

The npm package coa had versions published with malicious code. Users of affected versions (2.0.3 and above) should downgrade to 2.0.2 as soon as possible and check their systems for suspicious activity.

  • LOW
  • NETWORK
  • HIGH
  • CHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-506 - Embedded Malicious Code

The application contains code that appears to be malicious in nature.

Advisory Timeline

  • Published