Lodahs Package 0.0.1: Trojan Horse Targeting Cryptocurrency Wallets

Lodahs Package 0.0.1: Trojan Horse Targeting Cryptocurrency Wallets

CVE-2019-19771 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.

Learn more about our Web Application Penetration Testing UK.