# sonatype-2022-0216

## faker - Malicious Denial of Service (DoS) - Protestware

Published Jan 10, 2022

[bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/)

### Security Details

**CVE ID**: sonatype-2022-0216  
**CVE Description**: faker - Malicious Denial of Service (DoS) - Protestware  
**Published**: Jan 10, 2022  
**CVSS Score**: 7.5 High  
**CVSS Vector**: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H  
**EPSS Score**: 0%

### Malware

**KEV Status**: Not in KEV Catalog: No known exploits

### Affected Ecosystems

**Source**: Sonatype

### References

[bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/ "https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/")
