npm
Malicious z-shop-js-env @56.2.1
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 4:33 PM UTC
OSV ID
MAL-2026-727
Ecosystem
npm
Summary
The package z-shop-js-env was found to contain malicious code.
Source: amazon-inspector (c910274a4f0635a1545efdbfbd102ee02489acc2cc2e37c2c5bec67beb6ea1eb)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.