-= Per source details. Do not edit below this line.=-
The package sarumaan_a was found to contain malicious code.
The OpenSSF Package Analysis project identified 'sarumaan_a' @ 1.1.1 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"sha256": "936358da4e0584be78e54ed71a2f77b06fcde56b7a007877e52646da270b7fea",
"source": "ossf-package-analysis",
"modified_time": "2025-12-18T11:16:23Z",
"versions": [
"1.1.1"
],
"import_time": "2025-12-18T11:36:32.838857468Z"
},
{
"sha256": "e590ffec4a066c881351a8bc82b4bc1330751b9a879ec12b5dbb50d45ea5f37f",
"source": "ossf-package-analysis",
"modified_time": "2025-12-19T20:50:57Z",
"versions": [
"1.1.3"
],
"import_time": "2025-12-19T21:06:29.986447762Z"
},
{
"sha256": "44f1d6e1dae6e429d4b5cffe6573928f3e9f5f816a3676747d786bce3c32d175",
"source": "amazon-inspector",
"modified_time": "2025-12-22T21:23:26Z",
"versions": [
"1.1.1",
"1.1.3"
],
"import_time": "2025-12-22T21:36:25.131214462Z"
}
]
}