OpenSSF/OSV advisory MAL-2026-3327 confirms this npm version as malicious. The package capacitor-plugin-service-worker was found to contain malicious code.
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in capacitor-plugin-service-worker (npm)
Details
The package capacitor-plugin-service-worker was found to contain malicious code.
## Source: ossf-package-analysis (3f28ba8fd7638915ed1060990ac5bbe779c131ee7453a155248a2f5d9d8c8e53) The OpenSSF Package Analysis project identified 'capacitor-plugin-service-worker' @ 100.0.0 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
Decision reason
One or more suspicious static signals were detected.