This package runs commands in a pre-install script that exfils sensitive data to a attacker-controlled domain.
-= Per source details. Do not edit below this line.=-
{ "malicious-packages-origins": [ { "sha256": "35298cb0137beb074e5c89131f8473dffa66dfc4ef03c163e1f00888530b2d40", "import_time": "2025-02-03T18:37:54.4844072Z", "versions": [ "1.0.0" ], "id": "RLMA-2025-00238", "source": "reversing-labs", "modified_time": "2025-02-03T16:55:07Z" } ] }