This package runs commands in a pre-install script that exfils sensitive data to a attacker-controlled domain.
-= Per source details. Do not edit below this line.=-
{ "malicious-packages-origins": [ { "import_time": "2025-02-03T18:37:54.739182878Z", "id": "RLMA-2025-00243", "modified_time": "2025-02-03T16:55:19Z", "versions": [ "1.1.0" ], "source": "reversing-labs", "sha256": "956e185bcbe02573264003d5f115bee670502d2e2942bfacd1ecb30788559297" }, { "import_time": "2025-05-22T14:07:13.79537526Z", "id": "RLUA-2025-02833", "modified_time": "2025-05-22T12:47:59Z", "versions": [ "7.7.7", "7.7.8" ], "source": "reversing-labs", "sha256": "b020a93471303aa1915f088f4bab41d1c870b5a38441884d283101c268a43f93" } ] }