The package communicates with a domain associated with malicious activity.
-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'ngf-gov-hr-navbar' @ 0.2.20 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2025-07-14T12:10:39.947339452Z",
"sha256": "85f2baa5c5673490af93199349e0ef54f7c581115b1fa83d6df2c9e18430e031",
"source": "ossf-package-analysis",
"modified_time": "2025-07-14T12:05:52Z",
"versions": [
"0.2.20"
]
}
]
}