## Advisory https://github.com/advisories/GHSA-vxq2-vhm7-7mhq Currently pinned to `fetch-page-assets` `= 1.2.9`. ## Requested change Add these still-malicious versions: - `1.2.10` - `1.2.11` - `1.2.12` - `1.2.13` - `1.2.14` `1.2.13` and `1.2.14` are already in [MAL-2026-6358](https://osv.dev/vulnerability/MAL-2026-6358) (Amazon Inspector, 2026-08-25). `1.2.10`–`1.2.12` remain listed on the npm registry and were omitted from both this GHSA and the later Inspector additions. ## Public sources - OpenSourceMalware case study (tarball-verified `.vscode/tasks.json` auto-run on 1.2.10/1.2.11; 1.2.12 restored the fake-font payload plus a NullReceiver loader in `babel.config.cjs`): https://opensourcemalware.com/blog/polinrider-npm-case-study-dprk-attack - OSV update PR for MAL-2026-6358: https://github.com/ossf/malicious-packages/pull/1476 - npm packument still includes `1.2.10`, `1.2.11`, `1.2.12` (as of 2026-08-28) These GHSA malware records do not appear in this git tree, so this is an issue rather than an advisory-file PR.