OpenSSF/OSV advisory MAL-2026-16476 confirms this npm version as malicious.
Package source executes code through a VM context API.
lib/config-ui-server.jsView on unpkg · L3Package source references weak cryptographic algorithms.
lib/config-ui-server.jsView on unpkg · L3Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.sckit/darwin-amd64/sckitView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/memos-cloud-api.jsView on unpkgThis report applies to @memtensor/memos-cloud-openclaw-plugin@0.1.25.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source executes code through a VM context API.
lib/config-ui-server.jsView on unpkg · L3Package source references weak cryptographic algorithms.
lib/config-ui-server.jsView on unpkg · L3Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.sckit/darwin-amd64/sckitView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/memos-cloud-api.jsView on unpkg