npm

html-to-gutenberg @4.2.16

Vulnerability report · Last retrieved from osv.dev August 28, 2026 at 7:31 PM UTC

Malicious

OSV ID

MAL-2026-6359

Ecosystem

npm

Summary

Analysis of html-to-gutenberg@4.2.14 surfaced no a static rule matches and no traced behaviors indicating credential access, install-time remote code execution, silent relay of caller data, backdoor persistence, or dependency-tree hijack. No attacker-controlled network destinations, obfuscated payloads, or lifecycle-script droppers were identified in the package contents.

Source: amazon-inspector (3edf079490239b2b4c592ce4b7094c8089596437c15a73972ebd8282484a5273)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.