npm
Malicious post-purchase-bundler @99.9.25
Vulnerability report · Last retrieved from osv.dev June 23, 2026 at 4:30 AM UTC
OSV ID
MAL-2026-3412
Ecosystem
npm
Summary
The package post-purchase-bundler was found to contain malicious code.
Source: amazon-inspector (3a33aa69ef958573a786f3db208d8ee335829e14009d1fdafecbc842ed493b8b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.