Native filesystem events for Node.js ES6 - dependency confusion PoC by awais0x1 bugcrowd
OpenSSF/OSV advisory MAL-2026-3409 confirms this npm version as malicious. The package mw-filesystem-events-nodream was found to contain malicious code.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L109Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L7Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L8Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L8Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L8A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L109