GHSA-flagged malware brands - 16 autotel-*, 4 awaitly-*, and `ai-sdk-ollama` packages (Nov 2025–Jun 2026) marked embedded-malicious-code on 2026-06-29/30
GitHub's Advisory Database dropped CWE-506 (Embedded Malicious Code) records on 2026-06-29 and 2026-06-30 against 21 npm "brand" packages built up over months: the entire autotel-* observability family (16 packages, 400+ versions), the awaitly promise-utility family (4 packages, ~180 versions), and the ai-sdk-ollama Vercel AI-SDK typosquat (55 versions). Every published version of every listed package is now classified as malware.
Versions named here: 0.4.0, 0.5.0, 0.6.0, 0.6.1, 0.6.2, 0.6.3, 0.6.4, 0.6.5, 0.6.6, 0.7.0, 0.7.1, 0.8.0, 0.8.1, 0.9.0, 0.9.1, 0.10.0, 0.11.0, 0.11.1, 0.11.2, 0.12.0, 0.12.1, 0.13.0, 0.14.0, 0.14.1, 0.15.0, 0.15.1, 0.16.0, 0.17.0, 0.18.0, 0.18.1, 0.18.2, 0.18.3, 0.19.0, 0.19.1, 0.19.2, 0.19.3, 0.19.4, 0.19.5, 0.19.6, 0.19.7, 0.19.8, 0.19.9, 0.19.10, 0.19.13, 0.19.14, 0.19.15, 0.19.16, 0.19.17, 0.19.18, 0.19.19, 0.19.20, 0.19.21, 0.19.22, 0.19.23, 0.19.24, 0.19.25, 0.19.26, 0.19.27, 0.19.28, 0.19.29, 0.19.30, 0.19.31, 0.19.32, 0.19.33, 0.19.34, 0.19.35, 0.19.36