The package communicates with a domain associated with malicious activity.
-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'user_oidc' @ 8.0.2 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2025-10-22T23:05:36.182329804Z",
"source": "ossf-package-analysis",
"versions": [
"8.0.2"
],
"modified_time": "2025-10-22T22:40:50Z",
"sha256": "e28e6e5435f54199a3dca6186e1ad2d2846226bcf0a6792ff09d40b6215ed7af"
},
{
"import_time": "2025-10-23T15:06:43.7752139Z",
"source": "ossf-package-analysis",
"versions": [
"8.0.3"
],
"modified_time": "2025-10-23T14:43:46Z",
"sha256": "c735f97412c53181c344dda45b28cfe8f99d2125683693c3d097dc15722f76b3"
},
{
"id": "GHSA-xc3q-j43c-38v2",
"import_time": "2025-10-24T01:52:31.545667029Z",
"source": "ghsa-malware",
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"modified_time": "2025-10-24T01:36:04Z",
"sha256": "ab3ebb3b9bc178d18b199897b5d5d0492737f9ce310613487f3bd3e1278b086e"
}
]
}