npm

@antv/vendor @1.2.11

Vulnerability report · Last retrieved from osv.dev June 23, 2026 at 4:30 AM UTC

Malicious

OSV ID

MAL-2026-4093

Ecosystem

npm

Summary

The package @antv/vendor was found to contain malicious code.

Source: amazon-inspector (fa28e6b3b14fc90aaeb3ea0af39b5dc403645873ae6cc8e261a2de39502d09ac)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.