Skip to content

[pkg-vet-test][do-not-merge] S3 malware ref: flatmap-stream@0.1.1 (DEAD tarball, cannot install)#28

Open
Gldywn wants to merge 1 commit into
mainfrom
pkg-vet-test/s3-malware-flatmap-stream
Open

[pkg-vet-test][do-not-merge] S3 malware ref: flatmap-stream@0.1.1 (DEAD tarball, cannot install)#28
Gldywn wants to merge 1 commit into
mainfrom
pkg-vet-test/s3-malware-flatmap-stream

Conversation

@Gldywn

@Gldywn Gldywn commented May 29, 2026

Copy link
Copy Markdown
Owner

Throwaway fixture to verify pkg-vet + Aikido MALWARE detection. References flatmap-stream@0.1.1 (event-stream 2018 incident payload, OSV MAL-2025-20690). Registry tarball is HTTP 404 (taken down) and the lockfile entry has no integrity, so npm ci aborts at fetch before any lifecycle script: cannot be installed or executed. DO NOT MERGE; closed once the scan is captured.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant