-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'lululemon-b2b-utils' @ 95.999.0 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"versions": [
"95.999.0"
],
"import_time": "2025-11-19T19:35:12.674828915Z",
"source": "ossf-package-analysis",
"modified_time": "2025-11-19T19:10:47Z",
"sha256": "07945d7690ca8f065a6b9be67e6affbe9035dae5f6ab74fedaeaed3b75a9c3d7"
},
{
"versions": [
"97.999.0"
],
"import_time": "2025-11-20T04:07:44.16965257Z",
"source": "ossf-package-analysis",
"modified_time": "2025-11-19T20:50:47Z",
"sha256": "9a672aab9c1fab2b76a5941957a5b4c51ff96ee3bdaa79bf4cf6a65a3b816787"
}
]
}