npm
Malicious strapi-plugin-blurhash @3.6.8
Vulnerability report · Last retrieved from osv.dev June 23, 2026 at 3:29 AM UTC
OSV ID
MAL-2026-2452
Ecosystem
npm
Summary
The package strapi-plugin-blurhash was found to contain malicious code.
Source: amazon-inspector (75661495bed77534b8a415592110112986a3d2d48296f922b140d77d384d7df9)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.