-= Per source details. Do not edit below this line.=-
The package @bmg-web/bmg-ajax was found to contain malicious code.
The OpenSSF Package Analysis project identified '@bmg-web/bmg-ajax' @ 999.999.99 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2026-04-22T09:37:27.814733391Z",
"sha256": "9f62136cff515a9e7e387914d9d446eaf0c79eb13f653f1846a15ab4c495d56b",
"source": "ossf-package-analysis",
"modified_time": "2026-04-22T08:45:50Z",
"versions": [
"999.999.99"
]
},
{
"import_time": "2026-04-23T20:49:01.5317105Z",
"sha256": "a9d0060c1d5029ed1bcb3ed00c20e6a283a930b13d6e93072cebb3e97e45b78d",
"source": "amazon-inspector",
"modified_time": "2026-04-23T20:43:56Z",
"versions": [
"999.999.99"
]
}
]
}