SECURITY RESEARCH PLACEHOLDER — Reserved by Secur0 researcher ariverapoblet to demonstrate dependency-confusion exposure in miUrba (Alcazaba Beach SPA references @miurba/alcazaba). NOT for public consumption. Please contact security@miurba.com or via Secu
OpenSSF/OSV advisory MAL-2026-3410 confirms this npm version as malicious. The package @miurba/alcazaba was found to contain malicious code.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L7Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L8Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L8