nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
The product contains code that appears to be malicious in nature.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://nodesecurity.io/advisories/511 | third party advisory |