GHSA-flagged malware brands - 16 autotel-*, 4 awaitly-*, and `ai-sdk-ollama` packages (Nov 2025–Jun 2026) marked embedded-malicious-code on 2026-06-29/30
GitHub's Advisory Database dropped CWE-506 (Embedded Malicious Code) records on 2026-06-29 and 2026-06-30 against 21 npm "brand" packages built up over months: the entire autotel-* observability family (16 packages, 400+ versions), the awaitly promise-utility family (4 packages, ~180 versions), and the ai-sdk-ollama Vercel AI-SDK typosquat (55 versions). Every published version of every listed package is now classified as malware.
Versions named here: 29.0.0, 29.0.1, 29.0.2, 30.0.0, 30.0.3, 30.0.4, 30.0.5, 31.0.0, 31.0.1, 32.0.0, 32.0.1, 33.0.0, 33.0.1, 33.0.2, 34.0.0, 34.0.1, 34.0.2, 35.0.0, 36.0.0, 37.0.0, 38.0.0, 39.0.0, 40.0.0