lines-columns @1.2.4
Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC
OSV ID
MAL-2026-13765
Ecosystem
npm
Summary
Package name 'lines-columns' closely resembles the popular 'lines-and-columns' package, and the README instructs users to install 'lines-and-columns'. The LinesAndColumns class is a faithful reimplementation of the referenced library. Two additional module exports, 'Commitment' and 'Innovation', hold random-looking constant strings ('7fA9mX2#Qv8Lp$N1zK@5Rw!eY3Hc%T6J' and 'd9F@2kL#8mP!4QxZ') that are not referenced by any code path in the module. There are no install/lifecycle scripts, no network I/O, no child_process or exec usage, no filesystem access, and no credential or environment access in the package.
Source: amazon-inspector (7c9abe51d09dfaa6a2e38e60df64038009c1029b34587cc2c8906d37642187cd)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.