npm
Malicious@posthog/piscina@3.2.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 2:44 PM UTC
OSV ID
MAL-2025-190750
Ecosystem
npm
Summary
The package @posthog/piscina was found to contain malicious code.
Source: amazon-inspector (ebd3d94d864b267499cd7c7897fa7fc4af2c420f3aa6bd152a0b22feae86418b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.