npm
Malicious@silgi/yoga@0.7.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 7:45 PM UTC
OSV ID
MAL-2025-191320
Ecosystem
npm
Summary
The package @silgi/yoga was found to contain malicious code.
Source: amazon-inspector (7c8aabbdab5840682c4f335a1ae8ff93ff305af445e00bacb5f10b1fd85b7ba1)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.