npm

poly-provider-api @4.6.1

Vulnerability report · Last retrieved from osv.dev August 6, 2026 at 7:08 PM UTC

Malicious

OSV ID

MAL-2026-13381

Ecosystem

npm

Summary

No a static rule matches were produced for this package version, and traced-code findings are not available in a parseable form. The package's actual runtime and install-time behavior has not been characterized from the artifacts reviewed. Without concrete evidence of exfiltration, install-time code fetch/execute, silent-relay, credential distribution, backdoor, or self-propagation, no supply-chain attack class can be substantiated for this version.

Source: amazon-inspector (aef76fc9ad34b0c2f608bd61904deec5355ffe02b045eecf233e70e989ce0260)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.