Critical Malware Feed Entry Detected 2026-07-24
Malware feed entry — cross-referenced from OSV. This package is present in our corpus and is listed as malicious in the public OSV malicious-packages database. Our own scanners did not fire independently on it; we still publish it here so the lookup surface stays complete for tools that query the feed. See /advisories for hand-curated analyses.
Advisory · CLR-2026-80469

[email protected]

Confirmed malicious via cross-reference with OSV. Held in our corpus for lookup / queryable feed.

Detection details

[email protected] published to npm, cross-referenced from OSV on 2026-07-24 10:11 UTC.

Our detection pipeline did not fire on this package independently. It is listed here because the OSV public malicious-packages database has an entry for yuinpm, and we hold the artifact in our corpus — see the OSV reference in the sidebar.

OSV reference: MAL-2026-11039

This is an auto-generated entry in the codelake malware feed. Hand-curated deep case studies live on /advisories.