Loading npm security reports…
Security research placeholder published as part of authorized Rivian Bug Bounty disclosure (Intigriti report RIVIAN-79L374RT). The triager Aurelius explicitly invited this claim. Intended for transfer to Rivian Inc. Contact: pahpah@intigriti.me
OpenSSF/OSV advisory MAL-2026-3348 confirms this npm version as malicious. The package @rivianlabs/bedrock was found to contain malicious code.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L7