-= Per source details. Do not edit below this line.=-
The package @bmg-web/bmg-dropdown was found to contain malicious code.
The OpenSSF Package Analysis project identified '@bmg-web/bmg-dropdown' @ 999.9999.99 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"modified_time": "2026-04-22T08:47:48Z",
"versions": [
"999.9999.99"
],
"sha256": "8994c429cc6aa9f5645dc5fec50eb119d219ef5f111ebd83c2d234bd611f696e",
"source": "ossf-package-analysis",
"import_time": "2026-04-22T09:37:27.961897458Z"
},
{
"modified_time": "2026-04-23T20:43:56Z",
"versions": [
"999.9999.99"
],
"sha256": "ba8b2c9cb8ff59d283200d129e3ad62a7f469072326443114ebadcda2da4f894",
"source": "amazon-inspector",
"import_time": "2026-04-23T20:49:10.593962978Z"
}
]
}