npm
Malicious sarumaan_a @1.1.3
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 12:32 PM UTC
OSV ID
MAL-2025-192606
Ecosystem
npm
Summary
The package sarumaan_a was found to contain malicious code.
Source: amazon-inspector (44f1d6e1dae6e429d4b5cffe6573928f3e9f5f816a3676747d786bce3c32d175)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.