OpenSSF/OSV advisory MAL-2026-10892 confirms this npm version as malicious. claude-code-timer@1.0.0 was scanned with no findings of concern. No install-time lifecycle scripts, no outbound network calls to attacker-controlled destinations, no credential or environment scraping, no dropper or fetch-and-execute pattern, and no silent-relay behavior were observed. The package does not exhibit any of the supply-chain attack fingerprints this system is designed to catch.
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in claude-code-timer (npm)
Details
claude-code-timer@1.0.0 was scanned with no findings of concern. No install-time lifecycle scripts, no outbound network calls to attacker-controlled destinations, no credential or environment scraping, no dropper or fetch-and-execute pattern, and no silent-relay behavior were observed. The package does not exhibit any of the supply-chain attack fingerprints this system is designed to catch.
Decision reason
OpenSSF Malicious Packages via OSV confirms claude-code-timer@1.0.0 as malicious (MAL-2026-10892): Malicious code in claude-code-timer (npm)