Loading npm security reports…
Authorized security research placeholder (dependency-confusion proof-of-concept). Emits a benign out-of-band callback on install and does nothing else. Researcher: luq0x.
OpenSSF/OSV advisory MAL-2026-17642 confirms this npm version as malicious. personio-pipeline-projen presents itself as an authorized dependency-confusion proof-of-concept; the evidence does not identify a copied public package. Its preinstall hook runs on install with `node canary.js`...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThis report applies to personio-pipeline-projen@1.171.31.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L7