The new malware variant compromises thousands of npm repositories, stealing credentials and wiping directories if exfiltration fails.
CVE-2025-20341 (CVSS 8.8) allows low-privileged authenticated users to escalate to Administrator through crafted HTTP requests. No workarounds exist, and Cisco urges immediate upgrade to version 2.3.7.10-VA.
Esmeralda 1042, piso 10, CABA, Buenos Aires
Av. Tamboré, nº 267, 13º andar, conjunto 131, Torre Norte, Alphaville. CEP 06460-000, Cidade de Barueri - São Paulo
Cra. 45 #114-44. Oficina 404 Edificio Invention Center. Bogotá, Colômbia
Suecia 0155, Piso 14 7510114 Santiago, Providencia, Región Metropolitana, Chile
Av. Del Pinar 152 Of. 1101 Chacarilla del Estanque, Santiago de Surco, Lima