Logo
npm

@ai-vertical/ai-agent@1.0.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC

Malicious

OSV ID

MAL-2026-14070

Ecosystem

npm

Summary

On require/import, index.js fetches a hardcoded GitHub Gist (gist.github.com/aiverticalsolutions/7676451d2f972137d2482c4a8937a77a) via the api.github.com gists endpoint and passes the returned file contents directly to eval(). The gist is author-controlled and mutable, so whatever code the maintainer places there executes with the privileges of any process that loads this package. The package ships with empty description and empty author metadata and contains no other functionality — the remote-eval loader is the entire module.

Source: amazon-inspector (f3daa0f3fabdeebe3db0146233d623d65ae16aea601e54fd6519a160db5af8ee)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.