-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'blz-internal-pkg_update' @ 7.7.11 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"import_time": "2024-12-19T12:08:58.896188961Z",
"modified_time": "2024-12-19T11:55:53Z",
"source": "ossf-package-analysis",
"versions": [
"7.7.11"
],
"sha256": "8c0576719ed89c86b80e8064de18e089618752aa208fa88dfc410ad73e84bf8e"
},
{
"import_time": "2024-12-19T12:08:58.806459796Z",
"modified_time": "2024-12-19T11:50:49Z",
"source": "ossf-package-analysis",
"versions": [
"7.7.9"
],
"sha256": "932569e3f96886f9731675340f18ca15953074cb69922a6e77ef256b28b5363b"
},
{
"import_time": "2024-12-20T16:37:49.789561661Z",
"modified_time": "2024-12-20T16:31:03Z",
"source": "ossf-package-analysis",
"versions": [
"7.7.14"
],
"sha256": "22b7ba0d1c3b8e5b5dd1164d61508d7d0bf9932f8fd52521ac672c50cb822bdd"
},
{
"import_time": "2024-12-20T17:05:26.315186642Z",
"modified_time": "2024-12-20T16:38:11Z",
"source": "ossf-package-analysis",
"versions": [
"7.7.15"
],
"sha256": "a345201b8a7d112f2f876959b1a809c83236a7ab6d2f7136af1ab8362650a81c"
},
{
"import_time": "2024-12-20T17:05:26.387017047Z",
"modified_time": "2024-12-20T16:40:54Z",
"source": "ossf-package-analysis",
"versions": [
"7.7.16"
],
"sha256": "b5569612611d419e23a32156cb4d1119182a1e298dfd25a70741bdd62c83573e"
}
]
}