npm
Malicious@voiceflow/fetch@1.11.2
Vulnerability report · Last retrieved from osv.dev October 9, 2026 at 7:51 PM UTC
OSV ID
MAL-2025-191348
Ecosystem
npm
Summary
The package @voiceflow/fetch was found to contain malicious code.
Source: amazon-inspector (ae935a1a5c4c3792b0a6e51cfeca10ee5d11192e0928bf28ac3fd58ce89c24b7)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.