Malware advisory
MAL-2025-190880
Malicious code in @posthog/github-release-tracking-plugin (npm)
Affected packages
| Package | Ecosystem | Version | Verdict | Scanned (UTC) |
|---|---|---|---|---|
@posthog/github-release-tracking-plugin | npm | 0.0.7 | High risk | 2026-06-03 |
@posthog/github-release-tracking-plugin | npm | 0.0.6 | High risk | 2026-06-03 |