—
MAL-2026-6306
Malicious code in @gleamkit/probe (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (aaef237007e5d89031d334bf56a29892c7d6103aba9563b040556eea20ef2cfa) No suspicious behaviors were detected in this package. There are no lifecycle scripts performing remote fetches, no credential or environment scraping, no hardcoded exfiltration endpoints, and no obfuscated payloads. The package contents do not exhibit any of the known supply-chain attack fingerprints.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm / @gleamkit/probe
No fixed version published yet for @gleamkit/probe (npm). Pin to a known-safe version or switch to an alternative.