-= Per source details. Do not edit below this line.=-
The package onboarding-server was found to contain malicious code.
The OpenSSF Package Analysis project identified 'onboarding-server' @ 0.1.1 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"sha256": "9d8938c92b041ecea47a5e8d98398e602ff4f6dfe7ba405bc48f82de2654b5c4",
"import_time": "2026-03-26T14:37:17.249408233Z",
"modified_time": "2026-03-26T14:15:47Z",
"versions": [
"0.1.1"
],
"source": "ossf-package-analysis"
},
{
"sha256": "44d4a1844921cebc245e39614ba7b999c3890d048ad81429d89d9daf45038ecd",
"import_time": "2026-03-31T03:10:09.586695832Z",
"modified_time": "2026-03-31T02:07:58Z",
"versions": [
"0.1.1"
],
"source": "amazon-inspector"
}
]
}