Loading npm security reports…
takeover by dilosec
OpenSSF/OSV advisory MAL-2026-3397 confirms this npm version as malicious. The package tecken was found to contain malicious code.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L7Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9