npm

@gocortexio/npmgremlinbox-agpl-1-0-or-later @2.1.0

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-10785

Ecosystem

npm

Summary

No a static rule matches and no traced malicious behavior were observed in this package version. No credential access, no install/import-time network fetches, no lifecycle-script droppers, no silent-relay of caller-supplied data, and no dependency-chain hijack signals are present in the scanned files.

Source: amazon-inspector (1b9f161ff7fd8e7bf1fd1496277f6839c49d06cb7dd0e6daf772a019fb46b1cd)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.