npm

@gocortexio/npmgremlinbox-agpl-1-0 @2.1.0

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-10783

Ecosystem

npm

Summary

No a static rule matches and no traced installer-harm behaviors were identified in this package version. No lifecycle-script droppers, hardcoded exfiltration endpoints, credential-harvest code paths, or suspicious dependency-chain signals are present in the analyzed files.

Source: amazon-inspector (35ec6a36621ce352ab4510c339ef6a7367f88584b90ebfda17149c79dd947c66)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.