Investigate malicious npm packages reported through OSV and public advisories. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 23:59 UTC. Ordered by latest scan.
OpenSSF Malicious Packages via OSV confirms @client-web-next/icons@0.0.1 as malicious (MAL-2026-16503): Malicious code in @client-web-next/icons (npm)
OpenSSF Malicious Packages via OSV confirms @client-web-next/footer@0.0.1 as malicious (MAL-2026-16502): Malicious code in @client-web-next/footer (npm)
OpenSSF Malicious Packages via OSV confirms @client-web-next/feature-flags@0.0.1 as malicious (MAL-2026-16501): Malicious code in @client-web-next/feature-flags (npm)
OpenSSF Malicious Packages via OSV confirms @client-web-next/event-bus-listener@0.0.1 as malicious (MAL-2026-16500): Malicious code in @client-web-next/event-bus-listener (npm)