npm
Malicious sfx-data @99.0.0
Vulnerability report · Last retrieved from osv.dev June 23, 2026 at 3:29 AM UTC
OSV ID
MAL-2026-2801
Ecosystem
npm
Summary
The package sfx-data was found to contain malicious code.
Source: amazon-inspector (d3fe291f014f24a669e43d0092e768f822241c223899812aeeb652ade2dcc63f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.