-= Per source details. Do not edit below this line.=-
The package ally-starter-api was found to contain malicious code.
The OpenSSF Package Analysis project identified 'ally-starter-api' @ 99.99.99 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2026-05-04T03:13:21.516741406Z",
"versions": [
"99.99.99"
],
"sha256": "5479f46a56fc6576f3486d501685cddf5fe063c0acace5fbd2706cab928cde7d",
"modified_time": "2026-05-03T12:19:19Z",
"source": "ossf-package-analysis"
},
{
"import_time": "2026-05-04T23:49:24.812129938Z",
"versions": [
"100.0.0"
],
"sha256": "a12774becabc70e08211c6dc4b002e89e4385de1adae71a6bc7f3d117851afe9",
"modified_time": "2026-05-04T13:20:39Z",
"source": "ossf-package-analysis"
},
{
"import_time": "2026-05-12T07:28:55.317908443Z",
"versions": [
"99.99.99",
"100.0.0"
],
"sha256": "ac9875cbfe312bac49b96d321664e13d98ff6214d38db1d0b3339500a83204cc",
"modified_time": "2026-05-12T06:53:21Z",
"source": "amazon-inspector"
}
]
}