-= Per source details. Do not edit below this line.=-
The package eth-logger was found to contain malicious code.
The OpenSSF Package Analysis project identified 'eth-logger' @ 4.3.21 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"source": "ossf-package-analysis",
"versions": [
"4.3.21"
],
"import_time": "2026-04-24T06:46:17.336014851Z",
"modified_time": "2026-04-23T07:46:14Z",
"sha256": "028addf545d834096a4443644415ea2ec422310d4e413d6ded00fb87fdd4d74f"
},
{
"source": "ossf-package-analysis",
"versions": [
"4.3.20"
],
"import_time": "2026-04-24T06:46:17.093010097Z",
"modified_time": "2026-04-23T07:27:12Z",
"sha256": "834f2df77f9e1df7adc62cd44dad73791aba5e7043373b2c5258691014b42e5d"
},
{
"source": "amazon-inspector",
"versions": [
"4.3.21",
"4.3.20"
],
"import_time": "2026-05-12T07:28:51.297397086Z",
"modified_time": "2026-05-12T06:53:21Z",
"sha256": "843cae77c9aaf84bef1b7d5e46e27795d5203d2959a39b2797f0e1248b4995c7"
}
]
}