npm
Malicious@ensdomains/content-hash@3.0.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:45 PM UTC
OSV ID
MAL-2025-190666
Ecosystem
npm
Summary
The package @ensdomains/content-hash was found to contain malicious code.
Source: amazon-inspector (39aeb9f2a2d9a8ee1c57695456c8af6657d069eaee694ef7f8c128bb292bfabd)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.