npm
Malicious @zahlen/checkout @0.2.2
Vulnerability report · Last retrieved from osv.dev August 6, 2026 at 7:08 PM UTC
OSV ID
MAL-2026-13391
Ecosystem
npm
Summary
No a static rule or traced code paths flagged malicious behavior in this package. No lifecycle hooks fetching or executing remote content, no credential or environment scraping, no hardcoded exfiltration endpoints, no silent-relay of caller data, and no persistence mechanisms were observed.
Source: amazon-inspector (4d1a20d08b428711d9b8c349d981cf4997f086b8cbd8dce407ef26e02706f33e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.