-= Per source details. Do not edit below this line.=-
The package spire.officejs-common was found to contain malicious code.
The OpenSSF Package Analysis project identified 'spire.officejs-common' @ 1.0.0 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"sha256": "01a816c80acb9fa90987b7a9b2900835ff6303bda1ef3f9a83175b7dd0288dbd",
"source": "ossf-package-analysis",
"modified_time": "2026-01-05T00:45:36Z",
"import_time": "2026-01-05T00:56:20.048428066Z",
"versions": [
"1.0.0"
]
},
{
"sha256": "2d5bc6046960bccab3120bb794cc2c868fa2bb41e0d35028f39e2e9ca9033a80",
"source": "amazon-inspector",
"modified_time": "2026-01-08T09:02:00Z",
"import_time": "2026-01-08T09:11:30.989425389Z",
"versions": [
"1.0.0"
]
}
]
}