npm
Malicious statist-browser-typed-client-eventea.projects.pwahelp @35.8.0
Vulnerability report · Last retrieved from osv.dev August 10, 2026 at 10:20 PM UTC
OSV ID
MAL-2026-13671
Ecosystem
npm
Summary
Package contains no code paths that read installer secrets, fetch and execute remote content, relay caller data to third-party destinations, or establish persistence. No lifecycle scripts or import-time side effects with attacker-controlled network destinations are present.
Source: amazon-inspector (abd82004d1cbf2e4b6a3c77f48293b0d9638fe59592eb40291b6a332121f6fe6)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.