Logo
npm

@accordproject/concerto-metamodel@3.12.5

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:42 AM UTC

Malicious

OSV ID

MAL-2025-191174

Ecosystem

npm

Summary

The package @accordproject/concerto-metamodel was found to contain malicious code.

Source: amazon-inspector (1581131b6f7d752a2f26c167db5c144e33b737febc23f3e156f76a1b68e763ae)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.