Authorized security research - dependency confusion validation
Do not install. Package is flagged as malicious (advisory MAL-2026-1318).
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| critical | MAL-2026-1318 | Malicious code in @web-monorepo/fetchers (npm) | — |
MAL-2026-1318 — Malicious code in @web-monorepo/fetchers (npm)Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/@web-monorepo/fetchersFirst published · 2026-03-07T04:54:11.853Z
Last updated · 2026-03-07T04:54:12.076Z