npm

naughty-package @1.0.8

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 2:32 PM UTC

Malicious

OSV ID

MAL-2026-1093

Ecosystem

npm

Summary

The package naughty-package was found to contain malicious code.

Source: amazon-inspector (f541502f67ae3fc0e3558f52fb3e24b3857ab7bae8d0f8b45dc077d4d06ea0f7)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.