npm
Malicious @emilgroup/discount-sdk @1.14.0
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-2074
Ecosystem
npm
Summary
No a static rule matches and no traced-code findings were produced for this package version. The scanned contents show no lifecycle-hook execution, no remote fetch-and-execute, no credential or environment scraping, no hardcoded exfiltration endpoint, and no silent-relay or backdoor mechanism reaching the installer.
Source: amazon-inspector (f1865498ea5a64d42e7c20006c28291248357d4b6526192d3f3064d2c5e68263)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.