The package communicates with a domain associated with malicious activity.
-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'iwf-typescript-sdk' @ 1.0.0 (npm) as malicious.
It is considered malicious because:
{ "malicious-packages-origins": [ { "modified_time": "2025-07-05T10:39:43Z", "source": "ossf-package-analysis", "import_time": "2025-07-05T11:05:03.894603339Z", "versions": [ "1.0.0" ], "sha256": "530fe36127716ca30ac2612deda2d66daec5734e20e14ce9d0b10735ee64d330" } ] }