-= Per source details. Do not edit below this line.=-
The package @bmg-web/bmg-external-link was found to contain malicious code.
The OpenSSF Package Analysis project identified '@bmg-web/bmg-external-link' @ 999.9999.99 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"source": "ossf-package-analysis",
"import_time": "2026-04-22T09:37:27.493987132Z",
"modified_time": "2026-04-22T08:45:41Z",
"versions": [
"999.9999.99"
],
"sha256": "c90f21812ea920a529792be2cb58fac49a67f8c820098a263a2c88a8f2c56097"
},
{
"source": "amazon-inspector",
"import_time": "2026-04-23T20:48:58.23569321Z",
"modified_time": "2026-04-23T20:43:56Z",
"versions": [
"999.9999.99"
],
"sha256": "6373b00808251dd64521cfb1864a0bf382c5df23e976984dea8dbebf925bbb63"
}
]
}