Logo
npm

test-supply-npm-lib-4@3.3.6

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 7:13 AM UTC

Malicious

OSV ID

MAL-2026-17314

Ecosystem

npm

Summary

package.json declares a dependency sourced from a git URL (git+https://git@github.com/agustedone/test-supply-npm-git-prepare-proof-4.git) pinned to commit 0abd2c55e475f12f58fb67ac487db4c1b00cf597, rather than from the npm registry. On npm install, npm clones that GitHub repository and runs any lifecycle scripts it contains, including a prepare hook indicated by the dependency's name. The dependency source is an individual GitHub account (agustedone/...) unrelated to any established publisher, and the fetched code is not subject to npm registry review or integrity checks against a registry tarball. Whoever controls that GitHub repository controls code executed on the installer's machine at install time.

Source: amazon-inspector (44f10381ad047460986bbeedafad42f8c71db61fff98fe07c915cd0d3678d268)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.