AI
Supply chain trojan exfiltrates credentials
Local reference
Suspicious dependency
Inferred
Loading file contents…
Loading traits…
Identity
| SHA-256 | 33074bf1845801730e0ba69e9d2a1950ccf709ef4effa2f4674df42c175bb10f |
|---|---|
| Filename | @openzeppelin-4-contracts-1.0.1.tgz |
| Package | @openzeppelin-4/contracts |
| Version | 1.0.1 |
| PURL | pkg:npm/%40openzeppelin-4/[email protected] |
Origin
| Source | forager |
|---|---|
| Feed | ossf-malicious-packages |
| Ecosystem | javascript |
| Domain | cnpmjs.org |
| URL | https://r.cnpmjs.org/@openzeppelin-4/contracts/-/contracts-1.0.1.tgz |
Timeline
| First seen | 11 Aug 2026 12:27 UTC |
|---|---|
| First analyzed | 12 Aug 2026 04:08 UTC |
| Last analyzed | 12 Aug 2026 04:08 UTC |
| Last updated | 12 Aug 2026 04:08 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | promoter |
| Traits version | 73866 |
Not seeing what you expected? Let us know