-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| malicious-npm-package | npm | >= 0.0.0 |
The advisory describes embedded malicious code (CWE-506) but provides no specific code examples, commit diffs, or function names. While the attack vector involves PowerShell command execution (likely via Node.js child_process methods or postinstall scripts), the lack of concrete implementation details in the provided information makes it impossible to identify specific functions/paths with high confidence. The 'Current Vulnerable Functions' array is explicitly empty in the provided data, and no source code references are available to analyze.