npm
Malicious @tw-marionette/input @99.0.4
Vulnerability report · Last retrieved from osv.dev June 23, 2026 at 4:30 AM UTC
OSV ID
MAL-2026-3071
Ecosystem
npm
Summary
The package @tw-marionette/input was found to contain malicious code.
Source: amazon-inspector (c6b93bf39d5351c220722a3326600c9855309a8e76cb6e10b8cff20f0d9bb102)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.