-= Per source details. Do not edit below this line.=-
This package turned malicious in v1.0.16 and exfiltrates email data via BCC.
{
"malicious-packages-origins": [
{
"ranges": [
{
"events": [
{
"introduced": "1.0.16"
}
],
"type": "SEMVER"
}
],
"sha256": "b71142d16d8ed2a6e96b93be35b1378bad054d735c90ce0ab7b20979a8c40ba4",
"modified_time": "2025-09-26T04:14:45Z",
"source": "google-open-source-security",
"import_time": "2025-09-26T04:16:01.989306Z"
}
]
}