@nativescript-community/ui-pulltorefresh 2.5.5
Detects a supply chain compromise in NPM packages (TinyColor, CrowdStrike etc.)Downloads latest trufflehog release
SHA-25676ac7c1edf4c328f8b4cdc59835ca9ef470247c655feffa36f7f9fe06e3dba80
Also flagged by osv (MAL-2025-47161: Malicious code in @nativescript-community/ui-pulltorefresh (npm)) +2 more.