-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'esm-package' @ 7.0.1 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{ "malicious-packages-origins": [ { "import_time": "2025-08-31T05:05:42.995036212Z", "modified_time": "2025-08-31T04:39:01Z", "versions": [ "7.0.1" ], "sha256": "8a4ba538bc8091b62e85f28a97b03721a94f080141bd84534e559bc3fd908ea9", "source": "ossf-package-analysis" }, { "import_time": "2025-09-01T07:07:03.215212605Z", "modified_time": "2025-09-01T06:50:52Z", "versions": [ "7.0.2" ], "sha256": "cb730a153758ce4da5b782699db6523489a052e76d1774b9f078f808817690ce", "source": "ossf-package-analysis" } ] }