The package communicates with a domain associated with malicious activity.
-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified '@goes-funky/y42-vscode' @ 99.99.103 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2025-08-18T06:09:46.983922388Z",
"sha256": "f2e0a98abbd9d80612a2ceffc06aac69b23dd12331094d9588992d8789631cf4",
"modified_time": "2025-08-17T15:15:37Z",
"source": "ossf-package-analysis",
"versions": [
"99.99.103"
]
},
{
"import_time": "2025-08-29T06:41:59.774557891Z",
"sha256": "c7aeb1b5b43f11b4e6cb967078ed13aa4f9b991be0c208668092b61487ae5ab0",
"modified_time": "2025-08-28T07:13:44Z",
"source": "reversing-labs",
"id": "RLMA-2025-04315",
"versions": [
"9.9.9",
"99.99.99",
"99.99.100",
"99.99.101",
"99.99.103"
]
}
]
}