Logo
npm

@grab-food/order-sdk-web@49.9.9

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 6:32 AM UTC

Malicious

OSV ID

MAL-2026-15681

Ecosystem

npm

Summary

Package published under a scope impersonating the Grab food-ordering brand with no real functionality (index.js exports an empty object). Its sole dependency, grab-food-order-sdk-web-core@49.9.9, is pinned to a tarball URL at https://registry.grivy-packages.com/ — a lookalike domain outside the npm registry. Installing @grab-food/order-sdk-web@49.9.9 causes npm to fetch and install code from that attacker-controlled host into the installer's node_modules, bypassing npm registry inspection and running whatever lifecycle scripts and code the fetched tarball contains. This is a dependency-chain dropper: the visible package is a hollow lure, and the actual payload arrives via the non-registry dependency URL.

Source: amazon-inspector (aa9b56bb1d69dc16b6095faea196af99809ad805b400a3c6b5499f896c8d74c2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.