npm
Malicious @vpms/design-system @0.1.3
Vulnerability report · Last retrieved from osv.dev June 25, 2026 at 10:45 PM UTC
OSV ID
MAL-2026-6467
Ecosystem
npm
Summary
The OpenSSF Package Analysis project identified '@vpms/design-system' @ 0.1.3 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Source: ossf-package-analysis (321dc26d64d28a5a4f4d59f0d719944570cccc7e16173b205160b2db4e04720e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.