PkgRadar

Malware advisory

MAL-2025-190880

Malicious code in @posthog/github-release-tracking-plugin (npm)

4 affected releases in the PkgRadar corpus · published 2025-11-24 · upstream advisory

Affected packages

Every release listed here is malicious per this advisory and is blocked at the CI gate. The Static scancolumn is PkgRadar’s independent static-analysis result for that release — some malicious releases score low on static signals alone, which is why we also mirror the advisory as authoritative.

PackageEcosystemVersionStatic scanScanned (UTC)
@posthog/github-release-tracking-pluginnpm0.0.4High risk2026-08-12
@posthog/github-release-tracking-pluginnpm0.0.5Low risk2026-07-14
@posthog/github-release-tracking-pluginnpm0.0.6Low risk2026-07-14
@posthog/github-release-tracking-pluginnpm0.0.7Low risk2026-07-14

PkgRadar blocks these releases at the CI gate before they reach your build. Start free or see all advisories.

Malicious code in @posthog/github-release-tracking-plugin (npm) — malware advisory MAL-2025-190880 | PkgRadar