Malware advisories
Known malicious packages
Releases in the PkgRadar corpus that match a known-malicious advisory (OSV MAL- records). Each links to the affected packages and the upstream advisory.
| Advisory | Summary | Affected releases |
|---|---|---|
MAL-2026-2050 | Malicious code in @emilgroup/insurance-sdk (npm) | 10 |
MAL-2026-2051 | Malicious code in @emilgroup/insurance-sdk-node (npm) | 10 |
MAL-2026-3757 | Malicious code in claw-subagent-service (npm) | 8 |
MAL-2026-4533 | Malicious code in codebuff-cli (npm) | 8 |
MAL-2026-3609 | Malicious code in forge-jsxy (npm) | 7 |
MAL-2026-4288 | Malicious code in @jaggle/resizeobserves (npm) | 6 |
MAL-2026-4669 | Malicious code in shiroai (npm) | 6 |
MAL-2026-2046 | Malicious code in @emilgroup/document-sdk (npm) | 5 |
MAL-2026-2055 | Malicious code in @emilgroup/partner-sdk-node (npm) | 5 |
MAL-2026-2075 | Malicious code in @emilgroup/document-sdk-node (npm) | 5 |
MAL-2026-4346 | Malicious code in logger-draft (npm) | 5 |
MAL-2026-4394 | Malicious code in @ikyyofc/gemini-cli (npm) | 5 |
MAL-2026-4623 | Malicious code in npm-builderio-qwik-poc (npm) | 5 |
GHSA-c83v-7274-4vgp | Malicious website can execute commands on the local system through XSS in the OpenCode web UI | 4 |
MAL-2026-2041 | Malicious code in @emilgroup/claim-sdk (npm) | 4 |
MAL-2026-2042 | Malicious code in @emilgroup/claim-sdk-node (npm) | 4 |
MAL-2026-2052 | Malicious code in @emilgroup/notification-sdk-node (npm) | 4 |
MAL-2026-4350 | Malicious code in clobprice.api (npm) | 4 |
MAL-2024-1006 | Malicious code in @ebay/ui-core-react (npm) | 3 |
MAL-2026-2900 | Malicious code in dotenv-pack (npm) | 3 |
MAL-2026-2920 | Malicious code in buffer-util-extend (npm) | 3 |
MAL-2026-4348 | Malicious code in api-rs-node (npm) | 3 |
MAL-2026-4496 | Malicious code in bandkit (npm) | 3 |
MAL-2026-4600 | Malicious code in loading-session (npm) | 3 |
MAL-2026-4697 | Malicious code in twokey (npm) | 3 |
MAL-2025-190880 | Malicious code in @posthog/github-release-tracking-plugin (npm) | 2 |
MAL-2025-190946 | Malicious code in @posthog/drop-events-on-property-plugin (npm) | 2 |
MAL-2025-190947 | Malicious code in @posthog/plugin-server (npm) | 2 |
MAL-2025-6214 | Malicious code in ecinc-cloud-moaxmpp (npm) | 2 |
MAL-2026-2031 | Malicious code in @emilgroup/account-sdk (npm) | 2 |
MAL-2026-2032 | Malicious code in @emilgroup/account-sdk-node (npm) | 2 |
MAL-2026-2036 | Malicious code in @emilgroup/auth-sdk (npm) | 2 |
MAL-2026-2037 | Malicious code in @emilgroup/auth-sdk-node (npm) | 2 |
MAL-2026-2044 | Malicious code in @emilgroup/customer-sdk (npm) | 2 |
MAL-2026-2045 | Malicious code in @emilgroup/customer-sdk-node (npm) | 2 |
MAL-2026-2048 | Malicious code in @emilgroup/gdv-sdk (npm) | 2 |
MAL-2026-2049 | Malicious code in @emilgroup/gdv-sdk-node (npm) | 2 |
MAL-2026-2060 | Malicious code in @emilgroup/tenant-sdk (npm) | 2 |
MAL-2026-2061 | Malicious code in @emilgroup/tenant-sdk-node (npm) | 2 |
MAL-2026-2509 | Malicious code in @langgraphjs/toolkit (npm) | 2 |
MAL-2026-2891 | Malicious code in chai-as-init (npm) | 2 |
MAL-2026-2929 | Malicious code in path-extend (npm) | 2 |
MAL-2026-2930 | Malicious code in path-internal (npm) | 2 |
MAL-2026-3309 | Malicious code in google-cloud-secret-manager-config-poc (npm) | 2 |
MAL-2026-3311 | Malicious code in path-addon (npm) | 2 |
MAL-2026-3323 | Malicious code in paypal-payouts-bridge (npm) | 2 |
MAL-2026-4347 | Malicious code in @devcarron/clob (npm) | 2 |
MAL-2026-4349 | Malicious code in clob.api (npm) | 2 |
MAL-2026-4404 | Malicious code in @loans/vehicles-api (npm) | 2 |
MAL-2026-4435 | Malicious code in @service-suppliers/fetch_suppliers_action_saga (npm) | 2 |
MAL-2026-4436 | Malicious code in @service-suppliers/select-supplier-watcher-saga (npm) | 2 |
MAL-2026-4437 | Malicious code in @service-suppliers/set_selected_supplier (npm) | 2 |
MAL-2026-4438 | Malicious code in @service-suppliers/suppliers (npm) | 2 |
MAL-2026-4439 | Malicious code in @service-user-notifications/set_notifications_not_removable (npm) | 2 |
MAL-2026-4444 | Malicious code in @shwfed/nuxt (npm) | 2 |
MAL-2026-4473 | Malicious code in @zizie071/libsignal-node (npm) | 2 |
MAL-2026-4491 | Malicious code in authcascade (npm) | 2 |
MAL-2026-4542 | Malicious code in crypto-javascript (npm) | 2 |
MAL-2026-4543 | Malicious code in customerdigital-ui-containers-lib (npm) | 2 |
MAL-2026-4549 | Malicious code in dot-utils-plus (npm) | 2 |
MAL-2026-4561 | Malicious code in fe-utils-core (npm) | 2 |
MAL-2026-4565 | Malicious code in fnd-stores (npm) | 2 |
MAL-2026-4567 | Malicious code in freertc (npm) | 2 |
MAL-2026-4580 | Malicious code in http-uploader-dev (npm) | 2 |
MAL-2026-4592 | Malicious code in jsontoken-extend (npm) | 2 |
MAL-2026-4674 | Malicious code in superacli (npm) | 2 |
MAL-2026-4699 | Malicious code in utils-mf (npm) | 2 |
MAL-2026-4707 | Malicious code in vue-compiler-sfc-plugin (npm) | 2 |
MAL-2026-4778 | Malicious code in 1cat-tunnel-client-zx (npm) | 2 |
MAL-2026-4779 | Malicious code in ether-bn.js (npm) | 2 |
MAL-2026-4784 | Malicious code in react-ui-polyfills (npm) | 2 |
MAL-2026-4807 | Malicious code in shop-minis (npm) | 2 |
MAL-2026-4823 | Malicious code in msc-terminal (npm) | 2 |
MAL-2026-5163 | Malicious code in @emcd-vue/auth (npm) | 2 |
MAL-2026-5168 | Malicious code in vg-interaction-model (npm) | 2 |
MAL-2024-7463 | Malicious code in pempers (npm) | 1 |
MAL-2026-2491 | Malicious code in @not-nemo/crypto-tracker (npm) | 1 |
MAL-2026-2740 | Malicious code in chai-as-type (npm) | 1 |
MAL-2026-3337 | Malicious code in @t-in-one/save_application_hid_to_storage (npm) | 1 |
MAL-2026-3774 | Malicious code in ts-build-optimize (npm) | 1 |
MAL-2026-4132 | Malicious code in echarts-for-react (npm) | 1 |
MAL-2026-4153 | Malicious code in size-sensor (npm) | 1 |
MAL-2026-4171 | Malicious code in @mc-xp/mc-monolith-js-src-package (npm) | 1 |
MAL-2026-4252 | Malicious code in @43uh3ig43/telemetry-client (npm) | 1 |
MAL-2026-4255 | Malicious code in cdk-sagemaker-notebook-workflow (npm) | 1 |
MAL-2026-4274 | Malicious code in power-apps (npm) | 1 |
MAL-2026-4289 | Malicious code in @stockrepublic/republic-components (npm) | 1 |
MAL-2026-4344 | Malicious code in verify-mycommand (npm) | 1 |
MAL-2026-4345 | Malicious code in eo-terminal (npm) | 1 |
MAL-2026-4351 | Malicious code in @databus-service-ui/ui-event (npm) | 1 |
MAL-2026-4352 | Malicious code in xarc-webpack-cli (npm) | 1 |
MAL-2026-4356 | Malicious code in testing-on-npmjs (npm) | 1 |
MAL-2026-4378 | Malicious code in @databus-service-ui/scroll-up-content (npm) | 1 |
MAL-2026-4385 | Malicious code in @druids/ui (npm) | 1 |
MAL-2026-4396 | Malicious code in @izumiswap/sdk (npm) | 1 |
MAL-2026-4420 | Malicious code in @polka-ui/loader (npm) | 1 |
MAL-2026-4421 | Malicious code in @pulse-web-platform-core/scripts-loader (npm) | 1 |
MAL-2026-4475 | Malicious code in aes-decode-runner-pro (npm) | 1 |
MAL-2026-4488 | Malicious code in auth-basic-vault (npm) | 1 |
MAL-2026-4489 | Malicious code in auth0-templates-scripts (npm) | 1 |
MAL-2026-4504 | Malicious code in cami-design (npm) | 1 |
MAL-2026-4511 | Malicious code in chai-as-patch (npm) | 1 |
MAL-2026-4512 | Malicious code in chai-as-repaired (npm) | 1 |
MAL-2026-4521 | Malicious code in class-weaver (npm) | 1 |
MAL-2026-4523 | Malicious code in claude-channel-imessage (npm) | 1 |
MAL-2026-4536 | Malicious code in corelia (npm) | 1 |
MAL-2026-4537 | Malicious code in cosmosdb-server (npm) | 1 |
MAL-2026-4544 | Malicious code in cwao (npm) | 1 |
MAL-2026-4546 | Malicious code in cwao-units (npm) | 1 |
MAL-2026-4547 | Malicious code in cxpher-linux-arm32 (npm) | 1 |
MAL-2026-4550 | Malicious code in emojifancy-print (npm) | 1 |
MAL-2026-4557 | Malicious code in ezymail (npm) | 1 |
MAL-2026-4566 | Malicious code in fpjson-lang (npm) | 1 |
MAL-2026-4570 | Malicious code in gehneb (npm) | 1 |
MAL-2026-4573 | Malicious code in git-userhub (npm) | 1 |
MAL-2026-4575 | Malicious code in happy-dlscord.js (npm) | 1 |
MAL-2026-4576 | Malicious code in hardhat-gas-analytics (npm) | 1 |
MAL-2026-4577 | Malicious code in harness-skil (npm) | 1 |
MAL-2026-4581 | Malicious code in idlidosa (npm) | 1 |
MAL-2026-4588 | Malicious code in ionic-insta-api-wrapper (npm) | 1 |
MAL-2026-4589 | Malicious code in itc-actors-api (npm) | 1 |
MAL-2026-4590 | Malicious code in json-to-simple-graphql-schema (npm) | 1 |
MAL-2026-4591 | Malicious code in jsonbson (npm) | 1 |
MAL-2026-4599 | Malicious code in license-checker-plus (npm) | 1 |
MAL-2026-4603 | Malicious code in lynx-keeper (npm) | 1 |
MAL-2026-4604 | Malicious code in lynx-keeper-cli (npm) | 1 |
MAL-2026-4613 | Malicious code in monade (npm) | 1 |
MAL-2026-4615 | Malicious code in motion-tool (npm) | 1 |
MAL-2026-4620 | Malicious code in nikou-node (npm) | 1 |
MAL-2026-4622 | Malicious code in normalize-path-seq (npm) | 1 |
MAL-2026-4656 | Malicious code in raise-common-lib (npm) | 1 |
MAL-2026-4667 | Malicious code in seekcode (npm) | 1 |
MAL-2026-4670 | Malicious code in skills-detector (npm) | 1 |
MAL-2026-4672 | Malicious code in solidity-coverage-plus (npm) | 1 |
MAL-2026-4678 | Malicious code in sysnode (npm) | 1 |
MAL-2026-4680 | Malicious code in tailwind-style-typography (npm) | 1 |
MAL-2026-4681 | Malicious code in tailwind-typography-stylecss (npm) | 1 |
MAL-2026-4715 | Malicious code in weavedb-base (npm) | 1 |
MAL-2026-4716 | Malicious code in weavedb-client (npm) | 1 |
MAL-2026-4721 | Malicious code in weavedb-node-client (npm) | 1 |
MAL-2026-4722 | Malicious code in weavedb-offchain (npm) | 1 |
MAL-2026-4723 | Malicious code in weavedb-sdk (npm) | 1 |
MAL-2026-4728 | Malicious code in web-dotenv (npm) | 1 |
MAL-2026-4737 | Malicious code in your-unique-package-name1 (npm) | 1 |
MAL-2026-4738 | Malicious code in zest-product (npm) | 1 |
MAL-2026-4739 | Malicious code in zkjson (npm) | 1 |
MAL-2026-4781 | Malicious code in unique-id-64 (npm) | 1 |
MAL-2026-4785 | Malicious code in test-nonmal-pkg-5 (npm) | 1 |
MAL-2026-4792 | Malicious code in react-json-chalk (npm) | 1 |
MAL-2026-4793 | Malicious code in vxui-react (npm) | 1 |
MAL-2026-4796 | Malicious code in fastjsonlog (npm) | 1 |
MAL-2026-4797 | Malicious code in int-node (npm) | 1 |
MAL-2026-4798 | Malicious code in jsonlogbundler (npm) | 1 |
MAL-2026-4799 | Malicious code in pdf-lib-enhanced (npm) | 1 |
MAL-2026-4800 | Malicious code in web3-prices (npm) | 1 |
MAL-2026-4801 | Malicious code in web3.prc (npm) | 1 |
MAL-2026-4802 | Malicious code in xlsx-enhanced (npm) | 1 |
MAL-2026-4803 | Malicious code in @fhkry/baileys (npm) | 1 |
MAL-2026-4805 | Malicious code in metricflow-tracker (npm) | 1 |
MAL-2026-4806 | Malicious code in shizukyu (npm) | 1 |
MAL-2026-4808 | Malicious code in wm-idp-sdk (npm) | 1 |
MAL-2026-4817 | Malicious code in chainix (npm) | 1 |
MAL-2026-4818 | Malicious code in saturn-bail (npm) | 1 |
MAL-2026-4819 | Malicious code in token-me-uk (npm) | 1 |
MAL-2026-4822 | Malicious code in loadtest-browser-lib (npm) | 1 |
MAL-2026-4826 | Malicious code in wm-mapper (npm) | 1 |
MAL-2026-4827 | Malicious code in unleash-js (npm) | 1 |
MAL-2026-4833 | Malicious code in bulletproof-json (npm) | 1 |
MAL-2026-4836 | Malicious code in nemo-reporter (npm) | 1 |
MAL-2026-4838 | Malicious code in justsaying-docs (npm) | 1 |
MAL-2026-4839 | Malicious code in hellowornd (npm) | 1 |
MAL-2026-4840 | Malicious code in @bcs-bank-complex-ui/deeplink (npm) | 1 |
MAL-2026-4841 | Malicious code in @hcs-hybrid/uirouter-core (npm) | 1 |
MAL-2026-4846 | Malicious code in @service-suppliers/fetch-initial-suppliers-watcher-saga (npm) | 1 |
MAL-2026-4847 | Malicious code in @service-suppliers/fetch-suppliers-watcher-saga (npm) | 1 |
MAL-2026-4848 | Malicious code in @service-suppliers/fetch_initial_suppliers_action_saga (npm) | 1 |
MAL-2026-4849 | Malicious code in @service-suppliers/fetch_suppliers_country_list_action_saga (npm) | 1 |
MAL-2026-4850 | Malicious code in @service-suppliers/reset_country_list (npm) | 1 |
MAL-2026-4851 | Malicious code in @service-suppliers/set_country_list (npm) | 1 |
MAL-2026-4852 | Malicious code in @service-suppliers/set_initial_loaded (npm) | 1 |
MAL-2026-4853 | Malicious code in @service-suppliers/set_selected_supplier_action_saga (npm) | 1 |
MAL-2026-4854 | Malicious code in @service-suppliers/set_suppliers_data (npm) | 1 |
MAL-2026-4855 | Malicious code in @service-suppliers/set_suppliers_loading_start (npm) | 1 |
MAL-2026-4856 | Malicious code in @service-suppliers/set_suppliers_loading_stop (npm) | 1 |
MAL-2026-4857 | Malicious code in @service-user-notifications/reset_notifications_not_removable (npm) | 1 |
MAL-2026-4858 | Malicious code in @service-user-notifications/set_refresh_interval (npm) | 1 |
MAL-2026-4860 | Malicious code in @qlab/ui (npm) | 1 |
MAL-2026-4882 | Malicious code in @cloudplatform-single-spa/administration (npm) | 1 |
MAL-2026-4888 | Malicious code in @cloudplatform-single-spa/arenadata-db (npm) | 1 |
MAL-2026-4891 | Malicious code in @cloudplatform-single-spa/base-static-page (npm) | 1 |
MAL-2026-4893 | Malicious code in @cloudplatform-single-spa/business-solutions (npm) | 1 |
MAL-2026-4896 | Malicious code in @cloudplatform-single-spa/cloud-dns (npm) | 1 |
MAL-2026-4898 | Malicious code in @cloudplatform-single-spa/cnapp-ui (npm) | 1 |
MAL-2026-4901 | Malicious code in @cloudplatform-single-spa/cp-api-gw (npm) | 1 |
MAL-2026-4902 | Malicious code in @cloudplatform-single-spa/datagrid (npm) | 1 |
MAL-2026-4903 | Malicious code in @cloudplatform-single-spa/dataplatform (npm) | 1 |
MAL-2026-4909 | Malicious code in @cloudplatform-single-spa/dataplatform-metastore (npm) | 1 |
MAL-2026-4912 | Malicious code in @cloudplatform-single-spa/dataplatform-trino (npm) | 1 |
MAL-2026-4917 | Malicious code in @cloudplatform-single-spa/employees (npm) | 1 |
MAL-2026-4918 | Malicious code in @cloudplatform-single-spa/enterprise (npm) | 1 |
MAL-2026-4922 | Malicious code in @cloudplatform-single-spa/floating-ips (npm) | 1 |
MAL-2026-4926 | Malicious code in @cloudplatform-single-spa/logaas (npm) | 1 |
MAL-2026-4931 | Malicious code in @cloudplatform-single-spa/marketplace-gigachat (npm) | 1 |
MAL-2026-4933 | Malicious code in @cloudplatform-single-spa/ml-ai-agents-agent (npm) | 1 |
MAL-2026-4934 | Malicious code in @cloudplatform-single-spa/ml-ai-agents-agent-system (npm) | 1 |
MAL-2026-4952 | Malicious code in @cloudplatform-single-spa/monitoring (npm) | 1 |
MAL-2026-4967 | Malicious code in @cloudplatform-single-spa/security-groups (npm) | 1 |
MAL-2026-4972 | Malicious code in @cloudplatform-single-spa/ssh-keys (npm) | 1 |
MAL-2026-4975 | Malicious code in @cloudplatform-single-spa/support (npm) | 1 |
MAL-2026-4978 | Malicious code in @cloudplatform-single-spa/svp-baas (npm) | 1 |
MAL-2026-4984 | Malicious code in @cloudplatform-single-spa/svp-interfaces (npm) | 1 |
MAL-2026-4988 | Malicious code in @cloudplatform-single-spa/svp-s3-storage (npm) | 1 |
MAL-2026-5003 | Malicious code in @cloudplatform-single-spa/vpn (npm) | 1 |
MAL-2026-5028 | Malicious code in sorenson-webfonts (npm) | 1 |
MAL-2026-5031 | Malicious code in @capibar.chat/ui-kit (npm) | 1 |
MAL-2026-5032 | Malicious code in @sber-ecom-core/sberpay-widget (npm) | 1 |
MAL-2026-5033 | Malicious code in @t-in-one/add_app_middleware_token (npm) | 1 |
MAL-2026-5034 | Malicious code in @t-in-one/add_application (npm) | 1 |
MAL-2026-5035 | Malicious code in @t-in-one/add_application_service_token (npm) | 1 |
MAL-2026-5036 | Malicious code in @t-in-one/add_application_tid (npm) | 1 |
MAL-2026-5037 | Malicious code in @t-in-one/application_id_storage_key_token (npm) | 1 |
MAL-2026-5038 | Malicious code in @t-in-one/form_product_token (npm) | 1 |
MAL-2026-5039 | Malicious code in @t-in-one/get_application_hid (npm) | 1 |
MAL-2026-5040 | Malicious code in @t-in-one/only_difference_payload (npm) | 1 |
MAL-2026-5041 | Malicious code in @t-in-one/prefill_bundle_data_token (npm) | 1 |
MAL-2026-5042 | Malicious code in @t-in-one/prefill_credit_data_token (npm) | 1 |
MAL-2026-5043 | Malicious code in @t-in-one/prefill_transformers_data_token (npm) | 1 |
MAL-2026-5044 | Malicious code in @t-in-one/restore_application_hid_from_storage (npm) | 1 |
MAL-2026-5045 | Malicious code in @t-in-one/safe_local_storage_token (npm) | 1 |
MAL-2026-5046 | Malicious code in @t-in-one/send_add_application (npm) | 1 |
MAL-2026-5095 | Malicious code in @challenger6/vm-pattern-library (npm) | 1 |
MAL-2026-5098 | Malicious code in js-shared-modules (npm) | 1 |
MAL-2026-5110 | Malicious code in jingmeideshishi (npm) | 1 |
MAL-2026-5121 | Malicious code in nepsnowplow (npm) | 1 |
MAL-2026-5122 | Malicious code in picnic-react-mise-en-place (npm) | 1 |
MAL-2026-5132 | Malicious code in rookie-security-test-pkg (npm) | 1 |
MAL-2026-5150 | Malicious code in @aonunited/angular (npm) | 1 |
MAL-2026-5158 | Malicious code in page-info-service (npm) | 1 |
MAL-2026-5159 | Malicious code in po-ops-local-dev (npm) | 1 |
MAL-2026-5164 | Malicious code in @emcd-vue/b2b-pay-form (npm) | 1 |
MAL-2026-5165 | Malicious code in @emcd-vue/loans (npm) | 1 |
MAL-2026-5166 | Malicious code in sourceflow-tracker (npm) | 1 |
MAL-2026-5174 | Malicious code in nodemon-pack (npm) | 1 |
MAL-2026-5175 | Malicious code in webpack-json (npm) | 1 |