npm
Malicious clerk-next-fix-auth-protection @8.8.8
Vulnerability report · Last retrieved from osv.dev July 27, 2026 at 7:29 AM UTC
OSV ID
MAL-2026-11069
Ecosystem
npm
Summary
The OpenSSF Package Analysis project identified 'clerk-next-fix-auth-protection' @ 8.8.8 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
Source: ossf-package-analysis (11ae257db932f3501d4f9168d9fb3c7abbdb1c6dad37f5bab183785662b3d9b6)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.