npm

@gocortexio/npmgremlinbox-agpl-3-0 @2.1.0

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-10786

Ecosystem

npm

Summary

No a static rule matches and no traced-code findings indicate installer harm in this version. The package artifacts show no credential access, no install/import-time network fetch-and-execute, no lifecycle-hook exfiltration, no silent-relay to third-party endpoints, and no dependency-chain dropper signals.

Source: amazon-inspector (4d73fb2c55c8b46079aed067487fdfbd542e8308ed577463f7d9ab02a7c06447)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.