poly-provider-api @4.6.1
Vulnerability report · Last retrieved from osv.dev August 6, 2026 at 7:08 PM UTC
OSV ID
MAL-2026-13381
Ecosystem
npm
Summary
No a static rule matches were produced for this package version, and traced-code findings are not available in a parseable form. The package's actual runtime and install-time behavior has not been characterized from the artifacts reviewed. Without concrete evidence of exfiltration, install-time code fetch/execute, silent-relay, credential distribution, backdoor, or self-propagation, no supply-chain attack class can be substantiated for this version.
Source: amazon-inspector (aef76fc9ad34b0c2f608bd61904deec5355ffe02b045eecf233e70e989ce0260)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.