Logo
npm

golan125-homepage-test@1.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-10897

Ecosystem

npm

Summary

Package self-identifies as a security research test ('Security research test - do not install'). The package.json homepage field contains javascript:alert(document.domain), which is an XSS probe targeting any registry or UI frontend that renders homepage values as clickable links without sanitization. The package has no lifecycle scripts (no preinstall/install/postinstall), no network I/O, and index.js exports an empty object — installing or requiring this package does not harm the installer's machine. The XSS probe targets registry web UI rendering, not developers who install the package.

Source: amazon-inspector (705b0dc2e3b9aafb6d0e72ecb5ad51d873cd59104a045f74bb27161c87a24960)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.