Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16533 confirms this npm version as malicious. Malicious code in exodus-firestore-synchronize (npm)
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgThis report applies to exodus-firestore-synchronize@0.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg