This package is in our known-malicious corpus. Details below.
Flagged as malicious
malware, affects all versions
cvss
9.0
how bad it is if exploited, out of 10
epss
not scored
chance of exploitation in the next 30 days
xyz score
4.0
CyberXYZ composite, out of 10
fig. 01 — GHSA-wh87-3959-vfrq, the advisory selected below
// advisories
GHSA-wh87-3959-vfrq
CRITICAL
Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.