@public-for-cdao/signer in npm. Metadata and links only; package code and payload are never mirrored.
Loading the full malicious-package record.
Review this malicious package's identity, affected versions, and published evidence.
Fixed response action, not model-generated: Remove the listed versions, and rotate any secrets the package could reach.
MAL-2026-10888
@public-for-cdao/signer in npm. Metadata and links only; package code and payload are never mirrored.
Loading the full malicious-package record.