npm
Malicious web3-chain-sync @2.4.3
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 8:32 AM UTC
OSV ID
MAL-2026-748
Ecosystem
npm
Summary
The package web3-chain-sync was found to contain malicious code.
Source: amazon-inspector (e8092971594fb2e6c9a5748ec492ca88c9a8cc396917b314f09e5c3c85e0d130)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.