npm
Malicious root-locator @1.2.0
Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 10:37 PM UTC
OSV ID
MAL-2026-14009
Ecosystem
npm
Summary
The package was found to contain malicious code or consuming dependency that contains malicious code
Source: amazon-inspector (2028000ac5395ba0f5ddda0c3d9003770de8f14847dd2cebaeb04031bbcf9ce8)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.