npm
Malicious@ukg-oneapp/common-lib@99.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 2:44 PM UTC
OSV ID
MAL-2025-191563
Ecosystem
npm
Summary
The package @ukg-oneapp/common-lib was found to contain malicious code.
Source: amazon-inspector (b059e51ff63f10ad83b16a1eeebedec98eaba6ac470197fe119a0e5e404af75d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.