npm
Malicious merchant-rps @5.99.99
Vulnerability report · Last retrieved from osv.dev June 23, 2026 at 4:30 AM UTC
OSV ID
MAL-2026-2371
Ecosystem
npm
Summary
The package merchant-rps was found to contain malicious code.
Source: amazon-inspector (d3e16d7a1d2277acd9102268accb99bf0054cf39ee5141d0380f920fedcc8e59)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.