-= Per source details. Do not edit below this line.=-
The package revenuecat-mcp-extension was found to contain malicious code.
The OpenSSF Package Analysis project identified 'revenuecat-mcp-extension' @ 1.999.9 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"versions": [
"1.999.9"
],
"sha256": "f2fe5e1bdb9f7b14ace23a731732dc245ee759d3628d236e0e6417218e979d4c",
"modified_time": "2025-11-06T19:00:45Z",
"source": "ossf-package-analysis",
"import_time": "2025-11-06T19:06:08.046999136Z"
},
{
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "96f411f3e2786cc80d5d85bf7feb0c72705b6e5c95af9c002b0f716e0b15ea83",
"modified_time": "2025-11-09T00:17:09Z",
"source": "amazon-inspector",
"import_time": "2025-11-09T00:27:23.988028175Z"
}
]
}