The package communicates with a domain associated with malicious activity.
-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'qwant-search-extension' @ 10.0.6 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"sha256": "b62fa18764e78b78ad37bea56c978df2cba57aa015e3b3eb13b0fc74e05678b1",
"source": "ossf-package-analysis",
"modified_time": "2025-10-23T00:01:16Z",
"versions": [
"10.0.6"
],
"import_time": "2025-10-23T00:24:02.612457958Z"
},
{
"sha256": "fc6266d12cc5a5fde2751cbbd5120927324224297ca596759dbfa5abbc08c1c6",
"source": "ghsa-malware",
"modified_time": "2025-10-24T01:35:59Z",
"id": "GHSA-ghr2-6g4g-94h5",
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"import_time": "2025-10-24T01:52:31.542759815Z"
}
]
}