-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'stitch-ui-toolbox' @ 20.0.0 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"sha256": "2c675cc0896f40de8130f745d8d2c808793e5e15fc4f97753c3a27531cfe9e28",
"import_time": "2024-06-28T02:44:49.466555175Z",
"source": "reversing-labs",
"versions": [
"1.9.9",
"0.9.9",
"99.9.9",
"9.9.9"
],
"id": "RLMA-2024-01792",
"modified_time": "2024-06-25T13:02:06Z"
},
{
"sha256": "8b066f4bf8b652375a156c53e369c3a3c181fde39cd856e797ad5d2c492c0b79",
"import_time": "2024-10-24T00:58:22.746442832Z",
"source": "reversing-labs",
"modified_time": "2024-10-16T13:20:52Z",
"id": "RLUA-2024-07363"
},
{
"sha256": "10cb4544e5ccc9bc82ff8a0b5186a4b1e8475fa69f3ae396aab195042485b9ec",
"import_time": "2025-12-15T01:36:17.328106141Z",
"source": "ossf-package-analysis",
"versions": [
"20.0.0"
],
"modified_time": "2025-12-15T01:26:07Z"
}
]
}