The flagged packages have been unpublished from npm. An unpublished package can be republished by anyone, not just the original author, including a malicious entity. Please inspect those packages to ensure they include the content you expected. As the test is currently limited to packages unpublished by Azer, you can also compare their content to the repositories on Azer's GitHub account: https://github.com/azer?tab=repositories To learn more, see: