-= Per source details. Do not edit below this line.=-
This package is malicious and was compromised as part of the Mini Shai-Hulud campaign by the TeamPCP threat actor. The malicious payload steals credentials, and can propogate to NPM packages using credentials it finds.
{
"iocs": {
"domains": [
"zero.masscan.cloud"
]
},
"malicious-packages-origins": [
{
"import_time": "2026-05-13T03:26:12.284906Z",
"source": "google-open-source-security",
"sha256": "0bd33abd6fda35e856f8346fda5e85913ce2cad6b4d6c315a2e7138b867760aa",
"modified_time": "2026-05-13T03:14:00Z",
"versions": [
"5.0.2"
]
}
]
}