-= Per source details. Do not edit below this line.=-
This package is a malicious packages part of the Go BufferZoneCorp and RubyGems knot-theory clusters. The packages in this cluster steal credentials, set up ssh access and tamper with build/workflow environmetn variables.
{
"iocs": {
"urls": [
"https://webhook.site/49c21843-c27c-4a1b-b1f6-037c3998055f"
]
},
"malicious-packages-origins": [
{
"import_time": "2026-05-13T03:53:19.895958Z",
"sha256": "a4e4f74e90479d472a307d311d48214827e21cf93ecf9b0b62ff2cb72adb2c9e",
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"source": "google-open-source-security",
"modified_time": "2026-05-13T03:51:44Z"
}
]
}