Logo
npm

test-supply-npm-lib-4@3.3.4

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17314

Ecosystem

npm

Summary

package.json declares a dependency test-supply-npm-git-prepare-proof-4 whose value is a bare git URL (git+https://git@github.com/agustedone/test-supply-npm-git-prepare-proof-4.git) rather than a registry version range. On npm install, npm clones that repository at mutable HEAD and runs any lifecycle scripts (preinstall/install/postinstall/prepare) it contains, with no version pin, no commit SHA, and no integrity check. Whoever controls the referenced GitHub repository controls code that executes on the installer's machine at install time. The shipped package body is otherwise an inert stub — the manifest line itself is the delivery mechanism.

Source: amazon-inspector (80bcbaa6379206627641c70dd25da3c3adfd51337f9a378223a6f8f13c8ba3ed)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.