## Advisory https://github.com/advisories/GHSA-2gqj-wrf5-35w8 Currently lists `html-to-gutenberg` `= 4.2.11` and `= 4.2.14`. ## Requested change Add: - `4.2.12` - `4.2.13` - `4.2.15` - `4.2.16` Leave `4.2.14` as-is. Amazon Inspector reported no malware in that tarball; it is already listed. ## Public sources Same compromised maintainer (`digelim` / DiogoAngelim) as fetch-page-assets (GHSA-vxq2-vhm7-7mhq). `4.2.12`/`4.2.13` were published 2026-07-15 (same window as fetch-page-assets `1.2.10`/`1.2.11`). `4.2.15`/`4.2.16` were published 2026-08-23 (same account-wide burst as fetch-page-assets `1.2.13`/`1.2.14`). These four versions are still listed on npm. - OpenSourceMalware case study (GitHub repo re-infection in the August burst): https://opensourcemalware.com/blog/polinrider-npm-case-study-dprk-attack - OSV update PR for MAL-2026-6359: https://github.com/ossf/malicious-packages/pull/1477 Evidence for these four versions is correlative (same maintainer and publish windows, documented GitHub re-infection), not a separate tarball walkthrough. These GHSA malware records do not appear in this git tree, so this is an issue rather than an advisory-file PR.