CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
npm supply-chain record

MAL-2026-13737

@openzeppelin-4/contracts

@openzeppelin-4/contracts in npm. Metadata and links only; package code and payload are never mirrored.

Loading the full malicious-package record on demand…