npm
Malicious @gleamkit/probe @0.0.1
Vulnerability report · Last retrieved from osv.dev June 24, 2026 at 6:36 AM UTC
OSV ID
MAL-2026-6306
Ecosystem
npm
Summary
No suspicious behaviors were detected in this package. There are no lifecycle scripts performing remote fetches, no credential or environment scraping, no hardcoded exfiltration endpoints, and no obfuscated payloads. The package contents do not exhibit any of the known supply-chain attack fingerprints.
Source: amazon-inspector (aaef237007e5d89031d334bf56a29892c7d6103aba9563b040556eea20ef2cfa)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.