-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'proton-pfff' @ 99.99.5 (crates.io) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
The OpenSSF Package Analysis project identified 'proton-pfff' @ 99.99.5 (crates.io) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
{
"malicious-packages-origins": [
{
"sha256": "0aa190f5fe08b29ab6f7230c099bdc2a201b7d5212f434f9e44b2be1feba5de1",
"versions": [
"99.99.5"
],
"modified_time": "2026-07-08T00:55:46Z",
"source": "ossf-package-analysis",
"import_time": "2026-07-08T01:38:14.03669744Z"
},
{
"modified_time": "2026-07-18T02:44:23Z",
"versions": [
"99.99.5"
],
"sha256": "5acb95a7594a27e0298f3994338f43788dc9e4f46d5c467c54432fd020f48af4",
"id": "GHSA-2c45-qvwj-8jfx",
"source": "ghsa-malware",
"import_time": "2026-07-18T10:46:28.595890529Z"
}
]
}