-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'lsh' @ 99.0.1 (crates.io) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"modified_time": "2026-04-28T01:45:56Z",
"import_time": "2026-04-28T06:04:30.698576513Z",
"source": "ossf-package-analysis",
"sha256": "8cd6cecd3051e3998c5f96ec8dbe1bcfffc1ed7133d394a1779c8c1b0252c8c0",
"versions": [
"99.0.1"
]
},
{
"modified_time": "2026-04-28T13:41:20Z",
"import_time": "2026-04-28T14:18:17.125757194Z",
"source": "ossf-package-analysis",
"sha256": "0d659fd33aac3eba6d4a9616642cd843d8cb7ae8a7433d94cad9dade68235d9e",
"versions": [
"99.1.0"
]
}
]
}