npm
Malicious@posthog/gitub-star-sync-plugin@0.0.8
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:42 AM UTC
OSV ID
MAL-2025-190881
Ecosystem
npm
Summary
The package @posthog/gitub-star-sync-plugin was found to contain malicious code.
Source: amazon-inspector (4be422ec924addbeb23c34a8b3305835feb3d665ab57afdc1450734d0b10f5a4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.