A library for interacting with Catbox.moe written in TypeScript.
82%
Total Score
70
100
100
80
50
The release has no build attestation, trusted publisher identity, or staged publishing evidence. This leaves the relationship between the source repository and the published artifact less independently verifiable.
The package defines a prepack lifecycle script. Because it runs during packaging rather than consumer installation, it is a limited concern, but it adds some build-process complexity.
Only one registry account, depthbomb, has publish access. This is a single-publisher risk, although the linked repository shows that the same owner is actively maintaining the project.
The source repository is owned by the individual user depthbomb rather than an organization. This is consistent with the single-maintainer findings and provides no organizational succession signal.
All 6 recent commits came from one contributor, giving a 100% top-contributor share. With a user-owned project rather than organization backing, this is a genuine continuity risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10296 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. node-catbox is vulnerable to Improper Input Validation in versions 0.1.0 - 4.1.0. | 0.1.0 - 4.1.0 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.