OpenSSF/OSV advisory MAL-2026-6359 confirms this npm version as malicious. The tarball contains `.vscode/tasks.json` with a hidden task (`hide: true`, `runOn: folderOpen`, label `eslint-check`) whose command executes `node./public/fonts/fa-solid-400.woff2`. The referenced file is not a WOFF2 font; it is obfuscated Node.js source (hex-identifier obfuscator preamble `global.i = 'A8'; const _0x3d50aa=_0x4540;...`, `global.r=require`) that imports `http`, `https`, `zlib`, and...
This report applies to html-to-gutenberg@4.2.20.
4.2.11, 4.2.14, 4.2.12, 4.2.19, 4.2.20, 4.2.21
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.