Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16403 confirms this npm version as malicious. The package was found to contain malicious code or consuming dependency that contains malicious code
Package source references dynamic require/import behavior.
dist/index.cjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis report applies to node-env-buffer@2.2.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references dynamic require/import behavior.
dist/index.cjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkg