← back
CVE-2017-16077

CVE-2017-16077

EPSS 1.2%CWE-506
In short

A fake package named 'mongose' (mimicking the legitimate 'mongoose' library) was uploaded to npm with malicious code designed to steal environment variables from developers' machines. The package has since been removed.

Technical detail

A typosquatting attack leveraging npm's package registry where a malicious module executed code during installation to exfiltrate environment variables (potentially containing API keys, credentials, and secrets). The attack vector requires the developer to install the package, and the threat model assumes insufficient vetting of dependencies during the supply chain.

Summary generated and translated by AI from the official description.
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →