The module pandora-doomsday infects other modules. It's since been unpublished from the registry.
Replicating malicious code, including viruses and worms, will attempt to attack other systems once it has successfully compromised the target system or the product.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://nodesecurity.io/advisories/482 | third party advisory |