security holding package
Do not install. Package is flagged as malicious (advisory MAL-2025-40351).
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| critical | MAL-2025-40351 | Malicious code in yarn.lock (npm) | — |
MAL-2025-40351 — Malicious code in yarn.lock (npm)Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/yarn.lockFirst published · 2018-04-05T23:24:35.842Z
Last updated · 2018-04-05T23:24:35.966Z