The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
The product contains code that appears to be malicious in nature.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://nodesecurity.io/advisories/544 | third party advisory |