The package communicates with a domain associated with malicious activity.
-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'test4-ross4' @ 10.0.0 (npm) as malicious.
It is considered malicious because:
{ "malicious-packages-origins": [ { "source": "ossf-package-analysis", "modified_time": "2025-06-28T17:13:29Z", "import_time": "2025-06-30T07:36:38.644237531Z", "versions": [ "10.0.0" ], "sha256": "5962c10cf17cf50b17d1b79208e0d7712e6ce3d2b2755927cce8912ceede6a64" }, { "source": "ossf-package-analysis", "modified_time": "2025-06-28T17:19:45Z", "import_time": "2025-06-30T07:36:38.774132747Z", "versions": [ "10.0.1" ], "sha256": "726f29c42d94afa7d831d8156ed02480510085855ea8c001bbcb9d6248abea6b" } ] }