Withdrawn Advisory: mariadb was malware
High severity
GitHub Reviewed
Published
Jul 18, 2018
to the GitHub Advisory Database
•
Updated Apr 19, 2024
Withdrawn
This advisory was withdrawn on Apr 19, 2024
Description
Published to the GitHub Advisory Database
Jul 18, 2018
Reviewed
Jun 16, 2020
Withdrawn
Apr 19, 2024
Last updated
Apr 19, 2024
Withdrawn Advisory
This advisory has been withdrawn because MariaDB now owns https://www.npmjs.com/package/mariadb and the package is no longer malicious. This link is maintained to preserve external references.
Original Description
The
mariadb
package is a piece of malware that steals environment variables and sends them to attacker controlled locations.All versions have been unpublished from the npm registry.
Recommendation
As this package is malware, if you find it installed in your environment, the real security concern is determining how it got there.
If you have found this installed in your environment, you should:
Additionally, any service which may have been exposed via credentials in your environment variables, such as a database, should be reviewed for indicators of compromise as well.
References