-= Per source details. Do not edit below this line.=-
The package @cplace-workflow-fe/cf-workflow was found to contain malicious code.
The OpenSSF Package Analysis project identified '@cplace-workflow-fe/cf-workflow' @ 2.0.4 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2026-05-11T16:58:50.468447823Z",
"sha256": "b2500116350b47c62998ce7a19415357cb4384f0a1d0976e86cd042e2556b8ec",
"source": "ossf-package-analysis",
"modified_time": "2026-05-11T16:02:00Z",
"versions": [
"2.0.4"
]
},
{
"import_time": "2026-05-12T07:28:54.324841318Z",
"sha256": "aa219c5fdaf0ec8e6e0467fb1f23bfde9a07c18276187464062943e612848781",
"source": "amazon-inspector",
"modified_time": "2026-05-12T06:53:21Z",
"versions": [
"2.0.4"
]
}
]
}