OpenSSF/OSV advisory MAL-2026-6359 confirms this npm version as malicious. The package ships a.vscode/tasks.json with runOn=folderOpen, hide=true, and presentation.reveal=never that silently executes `node./public/fonts/fa-solid-500.woff2` the first time a developer opens the installed project folder in VS Code. The referenced file is not a font — it is a Node.js loader disguised alongside legitimate FontAwesome assets (weight 500 is not a real FontAwesome variant), padded with leading...
This report applies to html-to-gutenberg@4.2.21.
4.2.11, 4.2.14, 4.2.12, 4.2.19, 4.2.20, 4.2.21
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.