Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16364 confirms this npm version as malicious. package.json declares a dependency `leak-internal` whose source is the HTTPS tarball URL https://src-ssrf.bytedance.net/ssrf/probe.tgz rather than a registry version range. On `npm install`, npm fetches and installs whatever bytes that URL currently returns, executing any lifecycle scripts contained in the fetched tarball...
Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgThis report applies to bytepack-probe-a7x3@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg