Loading npm security reports…
Security research — scope ownership proof for dependency confusion report
OpenSSF/OSV advisory MAL-2026-3394 confirms this npm version as malicious. The package @gaia-codesearch/gaia-api-typescript was found to contain malicious code.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L7Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L7