The package communicates with a domain associated with malicious activity.
-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'scaleft' @ 1.7.7 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2025-08-18T06:09:44.105543978Z",
"sha256": "3b304783defab6618943757f6247da4093e044290fe48dcd911c3362d05502ad",
"source": "ossf-package-analysis",
"modified_time": "2025-08-09T11:41:05Z",
"versions": [
"1.7.7"
]
},
{
"id": "RLMA-2025-04676",
"import_time": "2025-08-29T06:42:35.485815525Z",
"sha256": "90f384f84a9f310cb431e04a8a2ac462b36d31eac6e261dcb9a2b65bceaa0f18",
"source": "reversing-labs",
"modified_time": "2025-08-28T07:39:48Z",
"versions": [
"1.7.7",
"1.7.8"
]
}
]
}