This package has dated incident reports relevant to its trust history. Check the affected releases and the response before drawing conclusions about its current version.
Wiz documented malicious releases following a maintainer account compromise. The payload targeted developer and cloud credentials and attempted to spread through package publishing.
Build provenance — the latest release carries no provenance attestation. Source: the registry.
Publishers on the registry — 2. Source: the registry.
Security policy — published. Source: the repository.
OpenSSF Scorecard — 5.1 / 10 on 2026-08-17. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.
Third-party facts checked today; registry facts on every crawl.
State history 1
When
Change
2026-09-05
first verdict: active
Supply-chain history 1
account hijacked2026-086.0.0
The maintainer’s GitHub account was compromised and malicious commits to main triggered releases, with valid provenance, whose pre-install step stole npm, GitHub, cloud and Vault secrets and republished every package the stolen tokens could reach.
Commits deleted and versions removed; the worm reached over 2,200 versions across 444 packages.
Source: Aikido, Datadog Security Labs and Sonatype analyses, 4–5 August 2026. History, not a warning about today — the verdict above is about maintenance now.
Badge
Drop this in your README. It re-renders itself as the verdict changes.