-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'sandstorm-widgets-nyse-website' @ 7.0.1 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"modified_time": "2025-01-28T01:55:48Z",
"versions": [
"7.0.1"
],
"sha256": "521032aa86f84d6ee0bb3ad2b7b97e43683ed2040212f5b7cb5359f10549fea6",
"source": "ossf-package-analysis",
"import_time": "2025-01-28T02:24:54.940846435Z"
},
{
"modified_time": "2025-01-28T02:40:44Z",
"versions": [
"7.0.2"
],
"sha256": "bc2410964901d6fc2a89d8dabd90d91d52808c5d1a52857d5f251682add9eb4b",
"source": "ossf-package-analysis",
"import_time": "2025-01-28T02:46:50.989657125Z"
},
{
"modified_time": "2025-03-03T13:38:38Z",
"versions": [
"7.0.0",
"7.0.1",
"7.0.2"
],
"sha256": "5c4ff648d6b3f905de1ae2e6ed2b78dd72c1e758bfe6c07c4e54c680b2e6378f",
"id": "RLMA-2025-01071",
"source": "reversing-labs",
"import_time": "2025-03-03T15:07:02.62475954Z"
}
]
}