OpenSSF/OSV advisory MAL-2026-17458 confirms this npm version as malicious. The package presents itself as a CSS custom-property polyfill for font translation, but its actual behavior is a browser-side code-smuggling vector. payload.css ships ten `--base-color-1`..`--base-color-10` custom properties whose values are hex-byte triplets; the file carries the literal marker `Payload for vantamods.online` and a `__DOMAIN__` placeholder (hex `5f5f444f4d41494e5f5f`). At runtime, translate.js reads...
This report applies to translate-base-font@1.4.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.