-= Per source details. Do not edit below this line.=-
The package supplychainsupplyer was found to contain malicious code.
The OpenSSF Package Analysis project identified 'supplychainsupplyer' @ 99.0.0 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"sha256": "b325304f2661df4b70ef4c1dc2448aea916eca0bdf8b84e93bc51f60d26179f9",
"import_time": "2025-11-05T10:39:41.287866497Z",
"source": "ossf-package-analysis",
"modified_time": "2025-11-05T10:32:54Z",
"versions": [
"99.0.0"
]
},
{
"sha256": "ffb82b4b36d6e82b7dff16e757aab9bf7ffce58bcd579bd38ad7cdd98da4c3e5",
"import_time": "2025-11-09T00:27:24.701097967Z",
"source": "amazon-inspector",
"modified_time": "2025-11-09T00:17:09Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
]
}
]
}