npm
Malicious@posthog/wizard@1.18.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 11:44 AM UTC
OSV ID
MAL-2025-190900
Ecosystem
npm
Summary
The package @posthog/wizard was found to contain malicious code.
Source: amazon-inspector (43ed05e891884ed2cf2d6f1790352cd3d07f97a03c6fb152561eb2e8b9d938c2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.