-= Per source details. Do not edit below this line.=-
The package @jesusvizcaino2021/com.baogong.app-push-permission was found to contain malicious code.
The OpenSSF Package Analysis project identified '@jesusvizcaino2021/com.baogong.app-push-permission' @ 101.1.3 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2026-04-20T04:35:29.112943136Z",
"sha256": "37f7f7df9a9aa6938faba3259c2b02334e7c84abd39ee1d649b56a57859c5560",
"source": "ossf-package-analysis",
"modified_time": "2026-04-15T08:18:47Z",
"versions": [
"101.1.3"
]
},
{
"import_time": "2026-04-23T20:49:06.182206961Z",
"sha256": "457170b51d87c7f84644a72a71a9979508a99061e7e8fdee3aa8c2e170493b12",
"source": "amazon-inspector",
"modified_time": "2026-04-23T20:43:56Z",
"versions": [
"101.1.3"
]
}
]
}