npm
Maliciousclaude-code-timer@1.0.0
Vulnerability report · Last retrieved from osv.dev September 6, 2026 at 6:01 AM UTC
OSV ID
MAL-2026-10892
Ecosystem
npm
Summary
claude-code-timer@1.0.0 was scanned with no findings of concern. No install-time lifecycle scripts, no outbound network calls to attacker-controlled destinations, no credential or environment scraping, no dropper or fetch-and-execute pattern, and no silent-relay behavior were observed. The package does not exhibit any of the supply-chain attack fingerprints this system is designed to catch.
Source: amazon-inspector (04950731ec6589eebae22166fb042e4253719f71bfd3fc2b58f28d26ede9e43c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.