This package runs commands in a pre-install script that exfils sensitive data to a attacker-controlled domain.
-= Per source details. Do not edit below this line.=-
{
"malicious-packages-origins": [
{
"id": "RLMA-2025-02653",
"import_time": "2025-05-22T14:06:42.54887224Z",
"modified_time": "2025-05-22T12:35:31Z",
"sha256": "dd8455bf8649ec6ee7c3263bd833fba5caa5db57aa241a52f3ec53b4b866235f",
"source": "reversing-labs",
"versions": [
"10.12.14"
]
}
]
}