npm
Malicious sugarball-cli @1.0.0
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 3:49 AM UTC
OSV ID
MAL-2026-14111
Ecosystem
npm
Summary
The package was found to contain malicious code or consuming dependency that contains malicious code
Source: amazon-inspector (e600e0ab4f99d726e508d2ad82425ab2bc06f141c333dfecf0bdba9edd66f6d3)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.