The package communicates with a domain associated with malicious activity.
-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'openai-tsp' @ 16.1.0 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"import_time": "2025-07-31T12:09:49.361481098Z",
"sha256": "9afad0907413b0e88664cb893d34b71ad10d4a15def77275bc4a654bb21dd7a8",
"source": "ossf-package-analysis",
"modified_time": "2025-07-31T11:40:47Z",
"versions": [
"16.1.0"
]
},
{
"import_time": "2025-08-01T16:42:51.047445846Z",
"sha256": "7a9abf0f83d648703200cfb077b7387e1cf3f0b899ca295f4c093c99c1ef588c",
"source": "ossf-package-analysis",
"modified_time": "2025-08-01T16:10:54Z",
"versions": [
"25.1.0"
]
}
]
}