AI
Supply chain attack exfiltrating credentials
Local reference
Suspicious dependency
Inferred
Loading file contents…
Loading traits…
Identity
| SHA-256 | d0ed7f2787f036ef0757e7eb9391ab9303c0351be51f0bed86ca010318581857 |
|---|---|
| Canonical SHA-256 | 2c91ad6e7d1381ae06344ff47e720fbca275321d61599123ac0258b208bdf460 |
| Filename | @openzeppelin-5-contracts-1.0.1.tgz |
| Package | @openzeppelin-5/contracts |
| Version | 1.0.1 |
| PURL | pkg:npm/%40openzeppelin-5/[email protected] |
Origin
| Source | harvest |
|---|---|
| Feed | supplychainattack.org |
| Ecosystem | javascript |
| Domain | npmjs.org |
| URL | https://registry.npmmirror.com/@openzeppelin-5/contracts/-/contracts-1.0.1.tgz |
Timeline
| First seen | 11 Aug 2026 10:46 UTC |
|---|---|
| First analyzed | 11 Aug 2026 15:27 UTC |
| Last analyzed | 11 Aug 2026 15:27 UTC |
| Last updated | 11 Aug 2026 15:27 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | promoter |
| Traits version | 73866 |
Not seeing what you expected? Let us know