vant is vulnerable to Malicious Code
100
Critical Risk
Affected versions of this package are vulnerable to embedded malicious code that executes during the postinstall script. The obfuscated malicious code, located in lib/util/support.js, activates a Monero cryptocurrency miner without user consent. This issue is resolved in versions 2.13.6, 3.6.16, and 4.9.15, where the malicious code has been removed. Users are strongly advised to upgrade to a secure version to mitigate this risk.
You are affected if you are using a version that falls within the vulnerable range.
vant is vulnerable to Malicious Code in versions 2.13.3 - 2.13.5, 3.6.13 - 3.6.15 and 4.9.11 - 4.9.14.
Upgrade the vant library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant