Backdoor / Malicious code
Critical severity
GitHub Reviewed
Published
Feb 23, 2021
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Withdrawn
This advisory was withdrawn on Feb 23, 2021
Description
Reviewed
Aug 28, 2019
Published to the GitHub Advisory Database
Feb 23, 2021
Withdrawn
Feb 23, 2021
Last updated
Jan 9, 2023
lita-coin 0.0.3 contains a backdoor mechanism that allows launching of hidden cryptocurrency mining operations inside the project. The code also contained a backdoor mechanism that allowed the attacker to send a cookie file back to a compromised project, and allow the attacker to execute malicious commands.
References