This package runs commands in a pre-install script that exfils sensitive data to a attacker-controlled domain.
-= Per source details. Do not edit below this line.=-
{
"malicious-packages-origins": [
{
"id": "RLMA-2025-02987",
"import_time": "2025-05-22T14:07:08.917936681Z",
"modified_time": "2025-05-22T12:58:42Z",
"sha256": "11274c2b092ed77dcc0c92cf27736e01b5a8aa8786d7cfe26019d04425f75897",
"source": "reversing-labs",
"versions": [
"10.10.10"
]
}
]
}