-= Per source details. Do not edit below this line.=-
The package eth-logger was found to contain malicious code.
The OpenSSF Package Analysis project identified 'eth-logger' @ 4.3.21 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"sha256": "028addf545d834096a4443644415ea2ec422310d4e413d6ded00fb87fdd4d74f",
"source": "ossf-package-analysis",
"modified_time": "2026-04-23T07:46:14Z",
"import_time": "2026-04-24T06:46:17.336014851Z",
"versions": [
"4.3.21"
]
},
{
"sha256": "834f2df77f9e1df7adc62cd44dad73791aba5e7043373b2c5258691014b42e5d",
"source": "ossf-package-analysis",
"modified_time": "2026-04-23T07:27:12Z",
"import_time": "2026-04-24T06:46:17.093010097Z",
"versions": [
"4.3.20"
]
},
{
"sha256": "843cae77c9aaf84bef1b7d5e46e27795d5203d2959a39b2797f0e1248b4995c7",
"source": "amazon-inspector",
"modified_time": "2026-05-12T06:53:21Z",
"import_time": "2026-05-12T07:28:51.297397086Z",
"versions": [
"4.3.21",
"4.3.20"
]
}
]
}