npm Update
3118Warning Date
Severity Level
Warning Number
Target Sector
24 October, 2021
● Critical
2021-3730
All
Description:
npm has released a security update to address a malware in the following product:
- ua-parser-js
- 0.7.29
- 0.8.0
- 1.0.0
Threats:
The package contains malicious code (Malware).
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.
Best practice and Recommendations:
The CERT team encourages users to review npm security advisory and apply the necessary update: