Logo
npm

ecto-cargo-wk1tm59a@99.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 1:33 PM UTC

Malicious

OSV ID

MAL-2026-10893

Ecosystem

npm

Summary

Package ecto-cargo-wk1tm59a@99.0.0 exhibits several contextual red flags worth human review: a randomized-suffix name pattern (-wk1tm59a) typical of disposable/throwaway publishes, an inflated 99.0.0 version typical of dependency-confusion / proof-of-concept publishes, and only 3 files in the tarball. Automated content inspection of the package's code did not produce a usable trace, but the content was non-trivial enough that an automated description could not be produced. No specific attacker domain, exfiltration endpoint, or install-time fetch-and-execute behavior has been concretely identified from the available evidence, so a public block verdict is not justified, but the combination of disposable-name shape, 99.0.0 version inflation, and untraced contents warrants human inspection before this package is trusted.

Source: amazon-inspector (ee496f01ecebc77637213e597ba523c8cccda7efcd65e7ad2e700d804553dd29)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.