npm

sugarball-cli @1.0.0

Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 3:49 AM UTC

Malicious

OSV ID

MAL-2026-14111

Ecosystem

npm

Summary

The package was found to contain malicious code or consuming dependency that contains malicious code

Source: amazon-inspector (e600e0ab4f99d726e508d2ad82425ab2bc06f141c333dfecf0bdba9edd66f6d3)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.