CWE-506— Embedded Malicious Code
The product contains code that appears to be malicious in nature.— MITRE CWE catalog
105 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-506page 2 of 3
- CVE-2025-59141HIGHCVSS 8.8EG 8.82025-09-15
simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken over after a phishing attack. Version 0.2.3 was published, functionally identical to the previous patch version, but w…
- CVE-2025-59140HIGHCVSS 8.8EG 8.82025-09-15
backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after a phishing attack. Version 0.2.1 was published, functionally identical to the previous patch version, but wi…
- CVE-2019-19771HIGHCVSS 8.8EG 8.82019-12-12
The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.
- CVE-2025-59038HIGHCVSS 8.6EG 8.62025-09-09
Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9.2 may have been briefly compromised by a malware campaign. The malicious code attempts to redirect crypto transactions…
- CVE-2025-59037HIGHCVSS 8.6EG 8.62025-09-09
DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages). An attacker published new versions of fou…
- CVE-2026-67595HIGHCVSS 8.1EG 8.12026-07-29
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that…
- CVE-2026-95831HIGHCVSS 7.8EG 7.82026-09-22
Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to …
- CVE-2021-22884HIGHCVSS 7.5EG 7.62021-03-03
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via…
- CVE-2017-16205HIGHCVSS 7.5EG 7.52018-06-07
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
- CVE-2017-16204HIGHCVSS 7.5EG 7.52018-06-07
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
- CVE-2017-16203HIGHCVSS 7.5EG 7.52018-06-07
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
- CVE-2017-16202HIGHCVSS 7.5EG 7.52018-06-07
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
- CVE-2017-16081HIGHCVSS 7.5EG 7.52018-06-07
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16080HIGHCVSS 7.5EG 7.52018-06-07
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16079HIGHCVSS 7.5EG 7.52018-06-07
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16078HIGHCVSS 7.5EG 7.52018-06-07
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16077HIGHCVSS 7.5EG 7.52018-06-07
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16076HIGHCVSS 7.5EG 7.52018-06-07
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16075HIGHCVSS 7.5EG 7.52018-06-07
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16074HIGHCVSS 7.5EG 7.52018-06-07
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16073HIGHCVSS 7.5EG 7.52018-06-07
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16072HIGHCVSS 7.5EG 7.52018-06-07
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16071HIGHCVSS 7.5EG 7.52018-06-07
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16070HIGHCVSS 7.5EG 7.52018-06-07
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16069HIGHCVSS 7.5EG 7.52018-06-07
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16068HIGHCVSS 7.5EG 7.52018-06-07
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16067HIGHCVSS 7.5EG 7.52018-06-07
node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16066HIGHCVSS 7.5EG 7.52018-06-07
opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16065HIGHCVSS 7.5EG 7.52018-06-07
openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16064HIGHCVSS 7.5EG 7.52018-06-07
node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16063HIGHCVSS 7.5EG 7.52018-06-07
node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16060HIGHCVSS 7.5EG 7.52018-06-07
babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16059HIGHCVSS 7.5EG 7.52018-06-07
mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16058HIGHCVSS 7.5EG 7.52018-06-07
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16057HIGHCVSS 7.5EG 7.52018-06-07
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16056HIGHCVSS 7.5EG 7.52018-06-07
mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16055HIGHCVSS 7.5EG 7.52018-06-04
`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16054HIGHCVSS 7.5EG 7.52018-06-04
`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16053HIGHCVSS 7.5EG 7.52018-06-04
`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16052HIGHCVSS 7.5EG 7.52018-06-04
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16051HIGHCVSS 7.5EG 7.52018-06-04
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16050HIGHCVSS 7.5EG 7.52018-06-04
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16049HIGHCVSS 7.5EG 7.52018-06-04
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16048HIGHCVSS 7.5EG 7.52018-06-04
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16046HIGHCVSS 7.5EG 7.52018-06-04
`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16045HIGHCVSS 7.5EG 7.52018-06-04
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16044HIGHCVSS 7.5EG 7.52018-06-04
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16062HIGHCVSS 7.5EG 7.52018-05-29
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16061HIGHCVSS 7.5EG 7.52018-05-29
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
- CVE-2017-16047HIGHCVSS 7.5EG 7.52018-05-29
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
Map vulnerabilities like CWE-506 to your infrastructure
EchelonGraph correlates every CVE — across CWE-506 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →