OsVault/npm/tar
npm2 critical

tar

254 known vulnerabilities · 2 critical · 12 high

CVE-2021-32804HIGH

Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization

Published Aug 3, 2021
CVE-2021-32803HIGH

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning

Published Aug 3, 2021
CVE-2024-28863MEDIUM

Denial of service while parsing a tar file due to lack of folders count validation

Published Mar 22, 2024
CVE-2015-8860HIGH

Symlink Arbitrary File Overwrite in tar

Published Oct 24, 2017
CVE-2026-23950

Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

Published Jan 21, 2026
CVE-2026-26960

Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction

Published Feb 18, 2026
CVE-2026-24842

node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

Published Jan 28, 2026
CVE-2021-37713HIGH

Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization

Published Aug 31, 2021
CVE-2026-31802

node-tar Symlink Path Traversal via Drive-Relative Linkpath

Published Mar 10, 2026
CVE-2021-37712HIGH

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

Published Aug 31, 2021
CVE-2021-37701HIGH

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

Published Aug 31, 2021
CVE-2026-23745

node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization

Published Jan 16, 2026
CVE-2026-29786

tar has Hardlink Path Traversal via Drive-Relative Linkpath

Published Mar 5, 2026
CVE-2025-64118

node-tar has a race condition leading to uninitialized memory exposure

Published Oct 30, 2025
CVE-2026-28452

OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)

Published Feb 18, 2026
CVE-2026-23889

pnpm has Windows-specific tarball Path Traversal

Published Jan 26, 2026
GHSA-2w79-r9g8-wmcr

OpenClaw: Voice-call still parses large WebSocket frames before start validation (Incomplete fix for CVE-2026-32062)

Published Apr 3, 2026
MAL-2025-192266

Malicious code in elf-stats-silvered-star-676 (npm)

Published Dec 3, 2025
CVE-2026-22177

OpenClaw's config env vars allowed startup env injection into service runtime

Published Mar 3, 2026
MAL-2025-2716

Malicious code in vistar-ad-clienttestadv3 (npm)

Published Mar 25, 2025
GHSA-hv93-r4j3-q65f

OpenClaw Hook Session Key Override Enables Targeted Cross-Session Routing

Published Feb 17, 2026
MAL-2026-889

Malicious code in responses-starter-app (npm)

Published Feb 13, 2026
CVE-2025-31476

tarteaucitron.js allows url scheme injection via unfiltered inputs

Published Apr 7, 2025
CVE-2025-59536

Claude Code can execute commands prior to the startup trust dialog

Published Oct 3, 2025
CVE-2025-56515

Fiora chat group avatar is vulnerable to XSS via SVG files

Published Oct 1, 2025
CVE-2025-59343

tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball

Published Sep 24, 2025
MAL-2024-9278

Malicious code in ts-jest-starter-kit (npm)

Published Oct 11, 2024
GHSA-3pm9-5j7m-59vc

OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config

Published Apr 3, 2026
CVE-2026-22809

tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability

Published Jan 13, 2026
GHSA-fqrj-m88p-qf3v

OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targets

Published Apr 7, 2026
CVE-2025-31475

tarteaucitron.js allows prototype pollution via custom text injection

Published Apr 7, 2025
GHSA-hhq4-97c2-p447

OpenClaw: Zalo webhook replay cache cross-target messageId scope bypass

Published Apr 2, 2026
CVE-2025-69874

nanotar is vulnerable to path traversal in parseTar() and parseTarGzip()

Published Feb 11, 2026
CVE-2021-23430HIGH

Directory Traversal in startserver

Published Sep 2, 2021
GHSA-xphh-5v4r-r3rx

PsiTransfer has Zip Slip Path Traversal via TAR Archive Download

Published Dec 30, 2025
MAL-2025-1608

Malicious code in material-start (npm)

Published Feb 28, 2025
MAL-2026-3054

Malicious code in @apple-pay-trust/start (npm)

Published Apr 25, 2026
MAL-2025-192173

Malicious code in elf-stats-sugarplum-star-404 (npm)

Published Dec 3, 2025
CVE-2026-27008

OpenClaw hardened the skill download target directory validation

Published Feb 18, 2026
MAL-2022-1597

Malicious code in bitski-quickstart (npm)

Published Jun 20, 2022
CVE-2026-32024

OpenClaw's avatar symlink traversal can expose out-of-workspace local files

Published Mar 3, 2026
MAL-2022-6295

Malicious code in starlink2 (npm)

Published Jul 25, 2022
MAL-2022-6296

Malicious code in starter-theme (npm)

Published May 18, 2022
MAL-2022-1147

Malicious code in astar-portal-test-depconf (npm)

Published Jul 25, 2022
MAL-2022-4722

Malicious code in msal-react-quickstart (npm)

Published Jun 20, 2022
MAL-2022-3491

Malicious code in gtarc-fs (npm)

Published Aug 19, 2022
CVE-2026-27903

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Published Feb 26, 2026
CVE-2026-33864

Convict has Prototype Pollution via startsWith() function

Published Mar 26, 2026
MAL-2022-6421

Malicious code in tarojs-plugin-platform-lark (npm)

Published Jun 20, 2022
CVE-2025-32395

Vite has an `server.fs.deny` bypass with an invalid `request-target`

Published Apr 11, 2025
MAL-2022-7120

Malicious code in wf-kyt-starter (npm)

Published Jun 20, 2022
MAL-2022-7121

Malicious code in wf-kyt-starter-universal (npm)

Published Jun 20, 2022
CVE-2025-48387

tar-fs can extract outside the specified dir with a specific tarball

Published Jun 3, 2025
GHSA-3p2x-hjxj-c7rv

Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

Published Mar 21, 2026
MAL-2023-8420

Malicious code in astar-portal (npm)

Published Nov 2, 2023
GHSA-42mx-vp8m-j7qh

OpenClaw: OpenShell `mirror` mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup

Published Apr 7, 2026
MAL-2024-1676

Malicious code in world-id-onchain-starter (npm)

Published Jun 27, 2024
GHSA-f7fh-qg34-x2xh

OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets

Published Apr 17, 2026
MAL-2022-4262

Malicious code in launcher-start-page (npm)

Published Jun 20, 2022
MAL-2022-6420

Malicious code in target-ui (npm)

Published Jun 20, 2022
MAL-2023-1070

Malicious code in @freestarcapital/collector-pipeline (npm)

Published Aug 9, 2023
MAL-2022-6449

Malicious code in telescope-avatar (npm)

Published Jun 20, 2022
GHSA-9mph-4f7v-fmvh

OpenClaw has agent avatar symlink traversal in gateway session metadata

Published Mar 4, 2026
MAL-2024-9458

Malicious code in monday-react-quickstart-app (npm)

Published Oct 22, 2024
CVE-2025-65099

Claude Code vulnerable to command execution prior to startup trust dialog

Published Nov 19, 2025
MAL-2023-811

Malicious code in startrek-client (npm)

Published Jan 30, 2023
GHSA-gw32-9rmw-qwww

svelte is vulnerable to XSS with textarea bind:value

Published Jan 16, 2026
MAL-2024-11054

Malicious code in nft-dapp-starter-kit (npm)

Published Nov 27, 2024
MAL-2025-191067

Malicious code in avvvatars-vue (npm)

Published Nov 24, 2025
MAL-2025-191089

Malicious code in express-starter-template (npm)

Published Nov 24, 2025
CVE-2025-1467

tarteaucitron Cross-site Scripting (XSS)

Published Feb 23, 2025
MAL-2023-8431

Malicious code in gatsby-starter-gitlab (npm)

Published Nov 5, 2023
CVE-2024-30564CRITICAL

@andrei-tatar/nora-firebase-common Prototype Pollution vulnerability

Published Apr 18, 2024
CVE-2025-31138

tarteaucitron.js allows UI manipulation via unrestricted CSS injection

Published Apr 7, 2025
GHSA-fv94-qvg8-xqpw

OpenClaw: SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host

Published Apr 2, 2026
MAL-2023-8605

Malicious code in starling-api-web-starter-kit (npm)

Published Nov 23, 2023
MAL-2023-8612

Malicious code in minotari_wallet_ff (npm)

Published Nov 24, 2023
MAL-2023-8337

Malicious code in daftar-situs-judi-slot-online-gacor-gampang-menang-2023 (npm)

Published Oct 12, 2023
CVE-2018-25058MEDIUM

Twitter-Post-Fetcher vulnerable to Use of Web Link to Untrusted Target with window.opener Access

Published Dec 29, 2022
MAL-2025-190901

Malicious code in @postman/final-node-keytar (npm)

Published Nov 24, 2025
MAL-2023-876

Malicious code in the-starch-solution-eat-the-foods-you-love-regain-your-health-and-lose-the-weight-for-good-by-john-a (npm)

Published May 10, 2023
MAL-2025-191306

Malicious code in @quick-start-soft/quick-markdown-print (npm)

Published Nov 24, 2025
GHSA-9wx7-jrvc-28mm

Signature verification vulnerability in Stark Bank ecdsa libraries

Published Nov 8, 2021
MAL-2025-191326

Malicious code in @trackstar/test-package (npm)

Published Nov 24, 2025
MAL-2024-10671

Malicious code in iconscout-unicons-tarball (npm)

Published Nov 13, 2024
CVE-2023-3620MEDIUM

tarteaucitron.js vulnerable to Cross-site Scripting

Published Jul 11, 2023
CVE-2023-38700LOW

matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms

Published Aug 4, 2023
CVE-2024-12905HIGH

tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File

Published Mar 27, 2025
MAL-2024-1738

Malicious code in ai-chatbot-starter (npm)

Published Jun 25, 2024
MAL-2024-8967

Malicious code in cktool.target.nodejs (npm)

Published Sep 25, 2024
MAL-2025-1169

Malicious code in ppcp-starter-node (npm)

Published Feb 3, 2025
CVE-2021-43785HIGH

Cross-Site Scripting Vulnerability in @joeattardi/emoji-button

Published Dec 1, 2021
GHSA-f3pv-wv63-48x8

Electron: Named window.open targets not scoped to the opener's browsing context

Published Apr 7, 2026
MAL-2025-191974

Malicious code in elf-stats-wintry-northstar-674 (npm)

Published Dec 3, 2025
MAL-2025-192485

Malicious code in elf-stats-cheery-northstar-345 (npm)

Published Dec 11, 2025
MAL-2025-192162

Malicious code in elf-stats-starlit-northstar-873 (npm)

Published Dec 3, 2025
MAL-2025-192163

Malicious code in elf-stats-starlit-rocket-905 (npm)

Published Dec 3, 2025
MAL-2025-192164

Malicious code in elf-stats-starlit-train-195 (npm)

Published Dec 3, 2025
CVE-2026-24909

vlt Mishandles Path Sanitization for tar

Published Jan 28, 2026
MAL-2025-2715

Malicious code in vistar-ad-clienttestadv2 (npm)

Published Mar 25, 2025
MAL-2026-2611

Malicious code in upstart-lending-status (npm)

Published Apr 12, 2026
MAL-2026-2612

Malicious code in upstart-loan-status (npm)

Published Apr 12, 2026
MAL-2026-2615

Malicious code in upstartadmindashboard- (npm)

Published Apr 12, 2026
MAL-2026-2616

Malicious code in upstartapplicationstatus (npm)

Published Apr 12, 2026
CVE-2026-28453

OpenClaw has Zip Slip path traversal in tar archive extraction

Published Mar 2, 2026
MAL-2023-639

Malicious code in noor_ul_iman_tarjuma_quran_pdf_free_free__kv (npm)

Published May 9, 2023
MAL-2025-2430

Malicious code in visitor-targeting (npm)

Published Mar 14, 2025
MAL-2022-2268

Malicious code in csvtarse (npm)

Published Aug 19, 2022
MAL-2025-191098

Malicious code in frontity-starter-theme (npm)

Published Nov 24, 2025
MAL-2025-4489

Malicious code in microbundle-starter (npm)

Published May 27, 2025
CVE-2025-58751

Vite middleware may serve files starting with the same name with the public directory

Published Sep 9, 2025
MAL-2025-192738

Malicious code in elf-stats-caroling-star-725 (npm)

Published Dec 23, 2025
MAL-2024-7700

Malicious code in bootstar (npm)

Published Jul 11, 2024
MAL-2026-2614

Malicious code in upstart.previewcss (npm)

Published Apr 12, 2026
MAL-2026-2613

Malicious code in upstart-offer-container (npm)

Published Apr 12, 2026
MAL-2026-2739

Malicious code in ccip-starter-kit-hardhat (npm)

Published Apr 16, 2026
MAL-2026-1572

Malicious code in transform-new-target (npm)

Published Mar 16, 2026
GHSA-r4q5-vmmm-2653

follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets

Published Apr 14, 2026
GHSA-5h2c-8v84-qpvr

OpenClaw shell-env fallback trusted startup env and could execute attacker-influenced login-shell paths

Published Mar 3, 2026
MAL-2026-2727

Malicious code in agent-starter (npm)

Published Apr 16, 2026
MAL-2025-192093

Malicious code in elf-stats-midnight-star-734 (npm)

Published Dec 3, 2025
GHSA-vfp4-8x56-j7c5

OpenClaw: Exec environment denylist missed high-risk interpreter startup variables

Published Apr 17, 2026
CVE-2026-32062

OpenClaw voice-call media stream validated streams after upgrade, which could allow pre-start unauthenticated sockets to increase resource pressure

Published Mar 2, 2026
MAL-2022-6419

Malicious code in target-global-mbox (npm)

Published Jun 20, 2022
CVE-2026-34226

Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies

Published Mar 29, 2026
GHSA-w9cg-v44m-4qv8

OpenClaw affected by BASH_ENV / ENV startup-file injection into spawned shell commands

Published Mar 3, 2026
CVE-2026-32043

OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

Published Mar 3, 2026
MAL-2025-190730

Malicious code in @ensdomains/ens-avatar (npm)

Published Nov 24, 2025
MAL-2025-192161

Malicious code in elf-stats-starlit-mitten-980 (npm)

Published Dec 3, 2025
CVE-2026-28469

OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting

Published Feb 18, 2026
MAL-2025-191994

Malicious code in elf-stats-bright-star-712 (npm)

Published Dec 3, 2025
CVE-2026-27009

OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection

Published Feb 18, 2026
MAL-2025-191987

Malicious code in elf-stats-starlit-ribbon-255 (npm)

Published Dec 3, 2025
MAL-2025-192129

Malicious code in elf-stats-shimmering-northstar-293 (npm)

Published Dec 3, 2025
MAL-2026-2793

Malicious code in pil2-stark-js (npm)

Published Apr 16, 2026
CVE-2021-3804HIGH

Inefficient Regular Expression Complexity in taro

Published Sep 20, 2021
MAL-2022-6986

Malicious code in vt-blockchain-bootcamp-starter-frontend (npm)

Published Jun 8, 2022
MAL-2022-4677

Malicious code in monday-integration-quickstart-app (npm)

Published Jun 20, 2022
MAL-2022-4678

Malicious code in monday-integration-quickstart-app-typescript (npm)

Published Jun 20, 2022
MAL-2025-2508

Malicious code in gatsby-starter-hello-world (npm)

Published Mar 18, 2025
MAL-2024-7816

Malicious code in ent-widget-military (npm)

Published Jul 27, 2024
MAL-2022-1973

Malicious code in codemirror-6-getting-started (npm)

Published Oct 31, 2022
MAL-2025-1660

Malicious code in pinterest-api-quickstart (npm)

Published Mar 1, 2025
MAL-2025-3120

Malicious code in start-state-machine (npm)

Published Apr 3, 2025
CVE-2025-5896

taro-css-to-react-native Regular Expression Denial of Service vulnerability

Published Jun 9, 2025
MAL-2025-191251

Malicious code in @oku-ui/avatar (npm)

Published Nov 25, 2025
MAL-2025-241

Malicious code in smaato-shared-ui-audience-targeting (npm)

Published Jan 20, 2025
MAL-2025-4069

Malicious code in com.meta.xr.sdk.avatars.sample.assets (npm)

Published May 21, 2025
MAL-2022-6294

Malicious code in stargate-docs (npm)

Published Jun 20, 2022
MAL-2025-192008

Malicious code in elf-stats-cocoa-northstar-632 (npm)

Published Dec 3, 2025
MAL-2022-6414

Malicious code in talon-template-starter (npm)

Published Jun 20, 2022
MAL-2022-6418

Malicious code in target-campaign-library (npm)

Published Jul 21, 2022
MAL-2023-8613

Malicious code in tari_wallet_ffi (npm)

Published Nov 24, 2023
MAL-2023-1058

Malicious code in infocaster-frontend-bootstrap-4-starter (npm)

Published Aug 5, 2023
CVE-2026-32041

OpenClaw: Browser control startup could continue unauthenticated after auth bootstrap failure

Published Mar 2, 2026
MAL-2022-7015

Malicious code in wad-workshop-starter (npm)

Published Jun 22, 2022
MAL-2023-8251

Malicious code in ktarco (npm)

Published Sep 26, 2023
GHSA-533q-w4g6-5586

PsiTransfer: Upload PATCH path traversal can create `config.<NODE_ENV>.js` and lead to code execution on restart

Published Apr 16, 2026
MAL-2022-2998

Malicious code in fed-challenge-starter (npm)

Published Jun 20, 2022
GHSA-w8g9-x8gx-crmm

OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable

Published Apr 9, 2026
MAL-2025-2439

Malicious code in starrocks (npm)

Published Mar 15, 2025
MAL-2026-129

Malicious code in aws-target-mediator (npm)

Published Jan 7, 2026
GHSA-rj39-33v7-9xrq

Duplicate Advisory: OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)

Published Mar 21, 2026
MAL-2022-2267

Malicious code in cstar-react-primitives (npm)

Published Jun 20, 2022
MAL-2022-4676

Malicious code in monday-integration-quickstart (npm)

Published Jun 20, 2022
MAL-2026-2846

Malicious code in eslint-plugin-totara (npm)

Published Apr 17, 2026
MAL-2024-7799

Malicious code in smart-input-textarea (npm)

Published Jul 24, 2024
MAL-2026-799

Malicious code in @rsgweb/rockstar-account (npm)

Published Feb 6, 2026
MAL-2022-7138

Malicious code in whistle-start (npm)

Published Jun 20, 2022
CVE-2018-20835HIGH

Improper Input Validation in tar-fs

Published May 1, 2019
MAL-2025-2717

Malicious code in vistar-ad-clienttestadv4 (npm)

Published Mar 25, 2025
MAL-2025-192477

Malicious code in elf-stats-candystriped-star-592 (npm)

Published Dec 11, 2025
CVE-2026-32056

OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)

Published Mar 3, 2026
MAL-2025-190819

Malicious code in @quick-start-soft/quick-document-translator (npm)

Published Nov 24, 2025
MAL-2025-48542

Malicious code in @jdtaro/dynamic-devtools-utils (npm)

Published Oct 21, 2025
MAL-2025-192758

Malicious code in start-log-backend (npm)

Published Dec 23, 2025
MAL-2025-192759

Malicious code in start-log-plugin (npm)

Published Dec 23, 2025
MAL-2025-2315

Malicious code in hardhat-ethers-react-ts-starter (npm)

Published Mar 12, 2025
MAL-2026-2617

Malicious code in upstartautoretailadmin (npm)

Published Apr 12, 2026
MAL-2026-2618

Malicious code in upstartdr (npm)

Published Apr 12, 2026
MAL-2025-3251

Malicious code in helper-compilation-targets (npm)

Published Apr 17, 2025
MAL-2024-1232

Malicious code in @lbnqduy11805/shiny-rotary-phone (npm)

Published Apr 10, 2024
MAL-2023-203

Malicious code in compute-starter-kit-assemblyscript-default (npm)

Published May 25, 2023
MAL-2025-192596

Malicious code in starling-api (npm)

Published Dec 16, 2025
MAL-2022-4309

Malicious code in line-liff-v2-starter (npm)

Published Jun 20, 2022
MAL-2023-8336

Malicious code in daftar-10-bandar-togel-singapore-terpercaya-agen-pay4d-terbesar-di-asia (npm)

Published Oct 12, 2023
MAL-2023-926

Malicious code in usaa-textarea (npm)

Published Mar 28, 2023
MAL-2022-373

Malicious code in @jumpstart-ui/utils (npm)

Published Jun 20, 2022
MAL-2023-675

Malicious code in pdf-gods-generals-the-military-lives-of-moses-the-buddha-and-muhammad-by-richard-a-gabriel-on-textbo (npm)

Published May 10, 2023
MAL-2025-192276

Malicious code in elf-stats-snowy-northstar-860 (npm)

Published Dec 3, 2025
MAL-2023-810

Malicious code in starbuckssystem (npm)

Published Mar 21, 2023
MAL-2026-2769

Malicious code in hardhat-starter-kit (npm)

Published Apr 16, 2026
MAL-2023-8504

Malicious code in plugin-getting-started (npm)

Published Nov 10, 2023
CVE-2023-37478HIGH

pnpm incorrectly parses tar archives relative to specification

Published Aug 1, 2023
MAL-2025-190820

Malicious code in @quick-start-soft/quick-git-clean-markdown (npm)

Published Nov 24, 2025
MAL-2025-190824

Malicious code in @quick-start-soft/quick-task-refine (npm)

Published Nov 24, 2025
MAL-2023-8252

Malicious code in ktarco1 (npm)

Published Sep 26, 2023
MAL-2023-8258

Malicious code in starcoffe (npm)

Published Sep 28, 2023
MAL-2025-1622

Malicious code in ragbot-starter (npm)

Published Feb 28, 2025
MAL-2026-3302

Malicious code in ally-starter-api (npm)

Published May 3, 2026
MAL-2025-190754

Malicious code in @postman/node-keytar (npm)

Published Nov 24, 2025
MAL-2026-3320

Malicious code in @google-pay-trust/start (npm)

Published May 4, 2026
MAL-2025-191307

Malicious code in @quick-start-soft/quick-markdown-translator (npm)

Published Nov 24, 2025
MAL-2025-191308

Malicious code in @quick-start-soft/quick-remove-image-background (npm)

Published Nov 24, 2025
MAL-2022-5647

Malicious code in react-full-stack-starter-client (npm)

Published Jun 20, 2022
MAL-2025-191503

Malicious code in start-internal (npm)

Published Dec 1, 2025
MAL-2025-1179

Malicious code in tinyquickstartreactnative (npm)

Published Feb 3, 2025
MAL-2022-5745

Malicious code in remote-pay-cloud-starter-example (npm)

Published Jun 20, 2022
MAL-2022-5746

Malicious code in remote-pay-cloud-starter-example-typescript (npm)

Published Jun 20, 2022
MAL-2024-11180

Malicious code in tauri-plugin-autostart-api (npm)

Published Dec 1, 2024
MAL-2025-1515

Malicious code in @starkgate-v2/web (npm)

Published Feb 21, 2025
MAL-2024-1090

Malicious code in starknet4 (npm)

Published Mar 12, 2024
MAL-2025-1904

Malicious code in my-node-startup (npm)

Published Mar 3, 2025
MAL-2025-190821

Malicious code in @quick-start-soft/quick-markdown (npm)

Published Nov 24, 2025
MAL-2025-190822

Malicious code in @quick-start-soft/quick-markdown-compose (npm)

Published Nov 24, 2025
MAL-2025-192106

Malicious code in elf-stats-northbound-star-801 (npm)

Published Dec 3, 2025
MAL-2022-3357

Malicious code in getting-started-rpi (npm)

Published Jun 20, 2022
MAL-2024-1214

Malicious code in @lbnqduy11805/cautious-octo-rotary-phone (npm)

Published Apr 10, 2024
MAL-2025-2103

Malicious code in discord-getting-started (npm)

Published Mar 4, 2025
MAL-2024-8714

Malicious code in dowload_ebok_lenin_y_el_totalitarismo_by_mauricio_rojas_szvld (npm)

Published Sep 3, 2024
MAL-2022-6293

Malicious code in starbuckssystem.website (npm)

Published Jul 21, 2022
MAL-2022-6616

Malicious code in totaralms (npm)

Published Jul 26, 2022
MAL-2025-191322

Malicious code in @trackstar/angular-trackstar-link (npm)

Published Nov 24, 2025
MAL-2025-191323

Malicious code in @trackstar/react-trackstar-link (npm)

Published Nov 24, 2025
MAL-2025-191324

Malicious code in @trackstar/react-trackstar-link-upgrade (npm)

Published Nov 24, 2025
MAL-2025-191325

Malicious code in @trackstar/test-angular-package (npm)

Published Nov 24, 2025
MAL-2025-190823

Malicious code in @quick-start-soft/quick-markdown-image (npm)

Published Nov 24, 2025
MAL-2023-781

Malicious code in smooch-api-quickstart-example (npm)

Published Jul 14, 2023
MAL-2025-343

Malicious code in packs-starter (npm)

Published Jan 22, 2025
MAL-2026-1252

Malicious code in pear-apps-utils-avatar-initials (npm)

Published Mar 5, 2026
CVE-2026-32044

OpenClaw skills-install-download: tar.bz2 extraction bypassed archive safety parity checks (local DoS)

Published Mar 3, 2026
MAL-2023-8738

Malicious code in element-block-starter (npm)

Published Dec 22, 2023
MAL-2026-694

Malicious code in tarax (npm)

Published Feb 3, 2026
MAL-2025-3677

Malicious code in @starkgate/web (npm)

Published May 7, 2025
MAL-2025-190768

Malicious code in devstart-cli (npm)

Published Nov 24, 2025
MAL-2024-10911

Malicious code in plaid-tiny-quickstart (npm)

Published Nov 24, 2024
MAL-2026-2619

Malicious code in upstartloans (npm)

Published Apr 12, 2026
MAL-2026-2620

Malicious code in upstartportal (npm)

Published Apr 12, 2026
CVE-2021-43571CRITICAL

Improper Verification of Cryptographic Signature in starkbank-ecdsa

Published Nov 10, 2021
MAL-2025-322

Malicious code in canva-connect-api-starter-kit (npm)

Published Jan 22, 2025
MAL-2022-2148

Malicious code in concatarraybuffer (npm)

Published Jun 20, 2022
MAL-2024-2798

Malicious code in ontology-starter-react-app (npm)

Published Jun 25, 2024
MAL-2024-1294

Malicious code in tari-explorer (npm)

Published Apr 22, 2024
MAL-2025-48022

Malicious code in astra-db-recommendations-starter (npm)

Published Oct 8, 2025
MAL-2025-190881

Malicious code in @posthog/gitub-star-sync-plugin (npm)

Published Nov 24, 2025
MAL-2026-1598

Malicious code in @emerald-react/avatar (npm)

Published Mar 18, 2026
MAL-2025-4288

Malicious code in starknet-types-07 (npm)

Published May 22, 2025
MAL-2024-8973

Malicious code in quickstart-calls-chat-integration (npm)

Published Sep 25, 2024
MAL-2026-758

Malicious code in tailwindcss-forms-starter (npm)

Published Feb 5, 2026
MAL-2025-4299

Malicious code in all-star-2019 (npm)

Published May 23, 2025
MAL-2026-1969

Malicious code in spstargm (npm)

Published Mar 20, 2026
MAL-2025-192935

Malicious code in ing-feat-mortgage-consent-starter (npm)

Published Dec 25, 2025
MAL-2025-3878

Malicious code in com.meta.xr.sdk.avatars (npm)

Published May 16, 2025
MAL-2025-3081

Malicious code in niji-react-textarea (npm)

Published Apr 2, 2025
Check your entire dependency tree at onceRun dependency scan →