—
MAL-2026-4838
Malicious code in justsaying-docs (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: ossf-package-analysis (e1728e1b0cb2ea174743b9e437b707c768bb8979ba6299fedabfd49ea8a7d8e2) The OpenSSF Package Analysis project identified 'justsaying-docs' @ 2.4.4 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm / justsaying-docs
No fixed version published yet for justsaying-docs (npm). Pin to a known-safe version or switch to an alternative.