The package communicates with a domain associated with malicious activity.
-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'world-id-poap' @ 1.0.0 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"modified_time": "2025-06-04T20:15:47Z",
"versions": [
"1.0.0"
],
"sha256": "bdb64432a67fa7109c5ee4d1d5b94d0127eaedab876302eb3b246ae55b111498",
"source": "ossf-package-analysis",
"import_time": "2025-06-04T20:34:21.274110485Z"
},
{
"modified_time": "2025-06-18T10:45:25Z",
"versions": [
"0.0.1",
"0.1.0",
"1.0.0"
],
"sha256": "02f118980d85e7a43ddaa6227f0908d64a1ba0f6cf823d84d5a6d7f5d4af2475",
"id": "RLMA-2025-03501",
"source": "reversing-labs",
"import_time": "2025-06-18T15:06:41.62310521Z"
}
]
}