Your plugin contains a malware nodeJS package.
…/LibraryIQ main 13:50
npm install
npm warn deprecated [email protected]: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful.
npm warn deprecated [email protected]: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting [email protected]
npm warn deprecated [email protected]: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting [email protected]
npm warn deprecated [email protected]: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting [email protected]
npm warn deprecated [email protected]: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting [email protected]
npm warn deprecated [email protected]: Please use @jridgewell/sourcemap-codec instead
npm warn deprecated [email protected]: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting [email protected]
npm error code E403
npm error 403 403 Forbidden - GET https://registry.npmjs.org/fs/-/fs-0.0.1-security.tgz
npm error 403 In most cases, you or one of your dependencies are requesting a package version that is forbidden by your security policy, or on a server you do not have access to.
npm error A complete log of this run can be found in: /home/pm/.npm/_logs/2026-07-05T11_50_41_957Z-debug-0.log
✗ Malicious package blocked
- [email protected]
Reference: https://app.safedep.io/community/malysis/01K32N96RPJWBP3M37FVWGWXWF
✗ PMG: 84 packages analyzed, 1 blocke
Your plugin contains a malware nodeJS package.
LibraryIQ/bun.lock
Line 478 in 054a7c2
https://app.safedep.io/community/malysis/01K32N96RPJWBP3M37FVWGWXWF
https://www.npmjs.com/package/fs
Originally posted by @PoorPocketsMcNewHold in SteamClientHomebrew/PluginDatabase#190 (comment)