-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'config-conventional' @ 20.1.1 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"id": "RLMA-2024-06343",
"import_time": "2024-10-24T00:56:17.105845825Z",
"modified_time": "2024-10-16T12:41:08Z",
"sha256": "5da07c9f7b4b3f7ade17d575798de3eaaf78405f6667073f06652dbc86eafca6",
"source": "reversing-labs",
"versions": [
"213.21.24"
]
},
{
"import_time": "2025-06-29T15:04:53.783053181Z",
"modified_time": "2025-06-29T14:38:54Z",
"sha256": "9db287fbaa3f09a3e8e30d18616b161cbc82f46c0867a4f8638067c82846d154",
"source": "ossf-package-analysis",
"versions": [
"20.1.1"
]
},
{
"id": "RLUA-2025-03806",
"import_time": "2025-08-01T10:41:36.377497335Z",
"modified_time": "2025-07-31T19:26:51Z",
"sha256": "84ae4232ef681a458ef8f06e4c4f2b14e4a092137af741653dfa463ff519d605",
"source": "reversing-labs",
"versions": [
"20.1.1"
]
}
]
}