CVE-2017-16077
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
In short
A fake package named 'mongose' (mimicking the legitimate 'mongoose' library) was uploaded to npm with malicious code designed to steal environment variables from developers' machines. The package has since been removed.
Technical detail
A typosquatting attack leveraging npm's package registry where a malicious module executed code during installation to exfiltrate environment variables (potentially containing API keys, credentials, and secrets). The attack vector requires the developer to install the package, and the threat model assumes insufficient vetting of dependencies during the supply chain.
Summary generated and translated by AI from the official description.
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Affected products
HackerOne · mongose node moduleReferences
https://nodesecurity.io/advisories/516