-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'vg-interaction-model' @ 40.0.1 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"source": "ossf-package-analysis",
"sha256": "aba91a5b2aeb99e94b28109825a7ac069669d39c12c118fd37d9ef70afe63261",
"modified_time": "2026-06-02T16:30:37Z",
"import_time": "2026-06-02T16:33:20.643494695Z",
"versions": [
"40.0.1"
]
},
{
"source": "ossf-package-analysis",
"sha256": "407173b2aee14360bfad38888d87727b81adef8528e3f63dd41520a6fd3ccabf",
"modified_time": "2026-06-02T19:35:35Z",
"versions": [
"40.0.4"
],
"import_time": "2026-06-03T03:16:20.383584507Z"
}
]
}