## Project setup ``` npm install ```
OpenSSF/OSV advisory MAL-2026-17418 confirms this npm version as malicious. On October 10, 2026 (local time), boom() calls localStorage.setItem('key', i) 100,000,000 times in a synchronous loop, potentially freezing a browser page. In version 0.0.2, the exported getCommonDateInRanges() calls boom() before input validation; the bundled source map confirms this path. Version 0.0.3 retains boom() as a separate export but no longer calls it from getCommonDateInRanges(), so an explicit call is...
This report applies to future-scripts@0.0.3.
0.0.2, 0.0.3
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.