npm

lines-columns @1.2.4

Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC

Malicious

OSV ID

MAL-2026-13765

Ecosystem

npm

Summary

Package name 'lines-columns' closely resembles the popular 'lines-and-columns' package, and the README instructs users to install 'lines-and-columns'. The LinesAndColumns class is a faithful reimplementation of the referenced library. Two additional module exports, 'Commitment' and 'Innovation', hold random-looking constant strings ('7fA9mX2#Qv8Lp$N1zK@5Rw!eY3Hc%T6J' and 'd9F@2kL#8mP!4QxZ') that are not referenced by any code path in the module. There are no install/lifecycle scripts, no network I/O, no child_process or exec usage, no filesystem access, and no credential or environment access in the package.

Source: amazon-inspector (7c9abe51d09dfaa6a2e38e60df64038009c1029b34587cc2c8906d37642187cd)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.