npm

commonweb-flow @99.99.99

Vulnerability report · Last retrieved from osv.dev August 7, 2026 at 2:10 AM UTC

Malicious

OSV ID

MAL-2025-6894

Ecosystem

npm

Summary

commonweb-flow@7.999.999 declares its sole dependency linker-event-header-serial as a direct tarball URL on artifacts.yosiroute.com (not the npm registry), and npm-shrinkwrap.json marks that dependency with hasInstallScript: true . On npm install , npm fetches the tarball from artifacts.yosiroute.com and runs its lifecycle install scripts, giving that host arbitrary code execution on the installer's machine. The tarball contents at that URL are mutable and can be swapped server-side without republishing commonweb-flow. Package metadata is placeholder ( author: "Package Registry" , description: "Generated package" , repository github.com/example/commonweb-flow ), and the manifest version 7.999.999 is inflated relative to the README/index.js self-reported 1.0.0 — the shape of a dependency-confusion lure aimed at internal builds that resolve commonweb-flow from the public registry over an internal package of the same name.

Source: amazon-inspector (e116400179d508d6dbe723a75f049d05218e1b019474bca84f2ed62537219572)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.