CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
npm supply-chain record

MAL-2026-13738

@openzeppelin-5/contracts

@openzeppelin-5/contracts in npm. Metadata and links only; package code and payload are never mirrored.

Loading the full malicious-package record on demand…