cache-poisoning-pwn-demo

Educational demo: a deliberately vulnerable npm package showing how GitHub Actions cache poisoning can produce a malicious release without stealing any credential. Do NOT use in production.

Package versions

19 VERSIONS IN TOTAL
versionpublisheddirect vulnerabilities
0.1.3214 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.3114 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.3014 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.2914 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.2814 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.2714 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.2614 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.2514 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.2414 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.2314 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.2214 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.2114 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.2014 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.1913 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.1813 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.1713 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.1613 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.1113 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L
0.1.013 May, 2026
  • 1
    C
  • 0
    H
  • 0
    M
  • 0
    L

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Get started free