delivery-ci-quality 35.6.2
Downloads and executes remote binaries
Library import stages and detaches a fetched executablenpm entry import conceals a native payload sidecar
SHA-2569e9eff36c275a82fa2b07bda2a497917dbacf3906fef83322b6c4bb2c6e58815
Also flagged by osv (MAL-2026-12679: Malicious code in delivery-ci-quality (npm)) +1 more.