-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'chkpkit' @ 99.99.9-9.99 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"import_time": "2025-01-23T12:45:58.451888271Z",
"sha256": "453a5a38c1ddda1304d12d5c7b494eaca1b2e5463c0685141485938fb0858948",
"source": "ossf-package-analysis",
"modified_time": "2025-01-23T12:15:54Z",
"versions": [
"99.99.94"
]
},
{
"import_time": "2025-01-23T12:45:58.559619841Z",
"sha256": "6a8be7f40bc28734ffc0196f3a098ced641af01dd4253dbbab0708289ebd5915",
"source": "ossf-package-analysis",
"modified_time": "2025-01-23T12:20:35Z",
"versions": [
"99.99.98"
]
},
{
"import_time": "2025-01-30T00:49:16.679669611Z",
"sha256": "2abd5e119e59d609551d6fcaf5128bad86491c26cc6b721014c324d54e930a7e",
"source": "ossf-package-analysis",
"modified_time": "2025-01-23T11:55:57Z",
"versions": [
"99.99.9-9.99"
]
},
{
"id": "RLMA-2025-00105",
"import_time": "2025-02-03T18:37:48.142310442Z",
"sha256": "e9cda78590b9a53e713b875e6cbe1fad937079b395ad98544db3bf7dd16f43fa",
"source": "reversing-labs",
"modified_time": "2025-02-03T16:49:01Z",
"versions": [
"99.99.99"
]
}
]
}