-= Per source details. Do not edit below this line.=-
The package eslint-plugin-totara was found to contain malicious code.
The OpenSSF Package Analysis project identified 'eslint-plugin-totara' @ 99.9.1 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"sha256": "b7e9a716caef417ea33ecefffca4e92e4e9d3b4e1f497bb15947fdca277f786c",
"modified_time": "2026-04-17T12:20:55Z",
"source": "ossf-package-analysis",
"import_time": "2026-04-17T12:27:28.941131509Z",
"versions": [
"99.9.1"
]
},
{
"sha256": "96447eb1f41df9da2d8e298530e25265374244a3e23279006ca447a8a5b0c0bd",
"modified_time": "2026-04-23T20:43:56Z",
"source": "amazon-inspector",
"import_time": "2026-04-23T20:49:09.113689222Z",
"versions": [
"99.9.1"
]
}
]
}