Package is malware. Hardcoded Telegram credentials, data exfiltration, and preinstall script execution indicate malicious intent.
-= Per source details. Do not edit below this line.=-
The package @telekom-wfa/auth-core was found to contain malicious code.
{
"malicious-packages-origins": [
{
"import_time": "2026-04-10T17:21:50.426527066Z",
"sha256": "9a2fe12e5542ae8cf1cf339c13c3480629ccfd6e2fb391427c4f1b17bbdc9f85",
"source": "amazon-inspector",
"modified_time": "2026-04-10T17:02:58Z",
"versions": [
"99.9.11"
]
}
]
}