Logo
npm

orbit-boxicons@2.1.3

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 3:44 PM UTC

Malicious

OSV ID

MAL-2025-190854

Ecosystem

npm

Summary

The package orbit-boxicons was found to contain malicious code.

Source: amazon-inspector (2bafb55d5f4d1082ed8b15fdeefee0570d3d86fe8b2a13bd046fd62abce85c18)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.