GHSA-flagged malware brands - 16 autotel-*, 4 awaitly-*, and `ai-sdk-ollama` packages (Nov 2025–Jun 2026) marked embedded-malicious-code on 2026-06-29/30
GitHub's Advisory Database dropped CWE-506 (Embedded Malicious Code) records on 2026-06-29 and 2026-06-30 against 21 npm "brand" packages built up over months: the entire autotel-* observability family (16 packages, 400+ versions), the awaitly promise-utility family (4 packages, ~180 versions), and the ai-sdk-ollama Vercel AI-SDK typosquat (55 versions). Every published version of every listed package is now classified as malware.
Versions named here: 1.0.0, 1.0.1, 2.0.0, 2.0.1, 3.0.0, 3.0.1, 4.0.0, 4.0.1, 4.0.2, 5.0.0, 5.0.1, 5.0.2, 6.0.0, 7.0.0, 8.0.0, 9.0.0, 10.0.0, 11.0.0