golan125-homepage-test@1.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-10897
Ecosystem
npm
Summary
Package self-identifies as a security research test ('Security research test - do not install'). The package.json homepage field contains javascript:alert(document.domain), which is an XSS probe targeting any registry or UI frontend that renders homepage values as clickable links without sanitization. The package has no lifecycle scripts (no preinstall/install/postinstall), no network I/O, and index.js exports an empty object — installing or requiring this package does not harm the installer's machine. The XSS probe targets registry web UI rendering, not developers who install the package.
Source: amazon-inspector (705b0dc2e3b9aafb6d0e72ecb5ad51d873cd59104a045f74bb27161c87a24960)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.