test-supply-npm-lib-4@3.3.6
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 7:13 AM UTC
OSV ID
MAL-2026-17314
Ecosystem
npm
Summary
package.json declares a dependency sourced from a git URL (git+https://git@github.com/agustedone/test-supply-npm-git-prepare-proof-4.git) pinned to commit 0abd2c55e475f12f58fb67ac487db4c1b00cf597, rather than from the npm registry. On npm install, npm clones that GitHub repository and runs any lifecycle scripts it contains, including a prepare hook indicated by the dependency's name. The dependency source is an individual GitHub account (agustedone/...) unrelated to any established publisher, and the fetched code is not subject to npm registry review or integrity checks against a registry tarball. Whoever controls that GitHub repository controls code executed on the installer's machine at install time.
Source: amazon-inspector (44f10381ad047460986bbeedafad42f8c71db61fff98fe07c915cd0d3678d268)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.