-= Per source details. Do not edit below this line.=-
The package lyft-ui was found to contain malicious code.
The OpenSSF Package Analysis project identified 'lyft-ui' @ 85.8.0 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2025-11-22T13:10:22.440253192Z",
"modified_time": "2025-11-22T12:47:35Z",
"source": "ossf-package-analysis",
"sha256": "1eca95468591ff582df3fadd1de8f6ffef5eb00720afbd1a511b5ea75ab55600",
"versions": [
"85.8.0"
]
},
{
"import_time": "2025-11-24T16:07:39.109214324Z",
"modified_time": "2025-11-24T15:54:02Z",
"source": "amazon-inspector",
"sha256": "70fc3f07a26106b927cf0e4fc2f5f7692c8392b48700359bccb2618bc1ac1565",
"versions": [
"85.8.0"
]
}
]
}