npm package report

Is @cap-js/sqlite safe?

This package is in our known-malicious corpus. Details below.

Flagged as malicious

  • credential_stealer, affects all versions
cvss
9.3

how bad it is if exploited, out of 10

epss
0.50%

chance of exploitation in the next 30 days

xyz score
4.6

CyberXYZ composite, out of 10

fig. 01 — GHSA-pvw4-cvr4-97p8, the advisory selected below

// advisories

GHSA-pvw4-cvr4-97p8

CRITICALCVE-2026-46421

On April 29, 2026, compromised versions of @cap-js/sqlite@2.2.2, @cap-js/postgres@2.2.2, and @cap-js/db-service@2.10.1 were published.

Affected
>=2.10.1, <2.11.0, = 2.2.2
Fixed in
2.3.0
Weakness
CWE-506
Published
2026-05-20
Source
osv

NVDMITREOSV


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 03:27 UTC. The most recent advisory here was published 2026-05-20. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @cap-js/sqlite safe? npm package security report | CyberXYZ