Big update!Introducing GitHub Bot Commands. Learn more
Socket
BlogLoveLog in
Book a demo

Bin script shell injection

Severity

High

Description

This package re-exports a well known shell command via an npm bin script. This is possibly a supply chain attack

Suggestion

Packages should not export bin scripts which conflict with well known shell commands


Packages with this issue

234Next
Socket

Product

Subscribe to our newsletter

Get open source security insights delivered straight into your inbox. Be the first to learn about new features and product updates.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc