A robust, performance-focused and full-featured Redis client for Node.js.
OpenSSF/OSV advisory MAL-2026-16390 confirms this npm version as malicious. The package publishes as `oracle-redis` but ships a verbatim copy of the ioredis README, source tree, and repository URL (`git://github.com/luin/ioredis.git`), presenting itself as ioredis under a different name. The `package.json` declares two additional runtime dependencies that are not part of ioredis's real dependency set and are never imported anywhere in the shipped `built/` source: `redis-type-intel` ^1.10.5...
This report applies to oracle-redis@5.11.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.