npm
Malicious @spinstorm/shared @99.99.99
Vulnerability report · Last retrieved from osv.dev June 23, 2026 at 3:29 AM UTC
OSV ID
MAL-2026-2998
Ecosystem
npm
Summary
The package @spinstorm/shared was found to contain malicious code.
Source: amazon-inspector (e56e452f9b6929e66be95ebdf49d432e7bbfeb76fc349123bcc39175f412e802)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.