Advisory
GHSA-2gqj-wrf5-35w8
Currently lists html-to-gutenberg = 4.2.11 and = 4.2.14.
Requested change
Add:
4.2.12
4.2.13
4.2.15
4.2.16
Leave 4.2.14 as-is. Amazon Inspector reported no malware in that tarball; it is already listed.
Public sources
Same compromised maintainer (digelim / DiogoAngelim) as fetch-page-assets (GHSA-vxq2-vhm7-7mhq). 4.2.12/4.2.13 were published 2026-07-15 (same window as fetch-page-assets 1.2.10/1.2.11). 4.2.15/4.2.16 were published 2026-08-23 (same account-wide burst as fetch-page-assets 1.2.13/1.2.14). These four versions are still listed on npm.
Evidence for these four versions is correlative (same maintainer and publish windows, documented GitHub re-infection), not a separate tarball walkthrough. These GHSA malware records do not appear in this git tree, so this is an issue rather than an advisory-file PR.
Advisory
GHSA-2gqj-wrf5-35w8
Currently lists
html-to-gutenberg= 4.2.11and= 4.2.14.Requested change
Add:
4.2.124.2.134.2.154.2.16Leave
4.2.14as-is. Amazon Inspector reported no malware in that tarball; it is already listed.Public sources
Same compromised maintainer (
digelim/ DiogoAngelim) as fetch-page-assets (GHSA-vxq2-vhm7-7mhq).4.2.12/4.2.13were published 2026-07-15 (same window as fetch-page-assets1.2.10/1.2.11).4.2.15/4.2.16were published 2026-08-23 (same account-wide burst as fetch-page-assets1.2.13/1.2.14). These four versions are still listed on npm.Evidence for these four versions is correlative (same maintainer and publish windows, documented GitHub re-infection), not a separate tarball walkthrough. These GHSA malware records do not appear in this git tree, so this is an issue rather than an advisory-file PR.