Logo
npm

@solana-labs/ancor@1.98.112

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-5786

Ecosystem

npm

Summary

Package is published as @solana-labs/ancor — a name one character off from anchor, the well-known Solana smart-contract framework (published as @coral-xyz/anchor, formerly @project-serum/anchor). The @solana-labs scope and the near-miss spelling ancor together create high confusion potential for developers searching for the Anchor framework. The shipped bundles lib/index.cjs.js and lib/index.esm.js are large minified rollups (~11k+ lines) that include require('child_process'), fetch(...) POST calls, and references to curl / ping. Pattern matches on keyword co-occurrence in a minified bundle do not by themselves prove malicious intent — Anchor and similar frameworks legitimately bundle child_process and HTTP for build/CLI tooling — but the combination of a typosquat-shaped name, a vendor-impersonating scope, and a large opaque bundle warrants human review before this version is allowed into installer environments. A reviewer should verify scope ownership (is @solana-labs actually controlled by Solana Labs, or a squatted scope?), de-minify the flagged regions around lines 5016/5046 and 11336/11441 to confirm whether the POST/fetch destinations and child_process spawns are part of a documented build/CLI flow or an exfiltration path, and compare bundle behavior against legitimate @coral-xyz/anchor.

Source: amazon-inspector (3265b293c8d6ebf4e866644687ab8bb9f03345c704acf7c885574886ad396b5b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.