@nativescript-community/ui-pulltorefresh 2.5.7
Exfiltrates secrets to webhook.site
Detects a supply chain compromise in NPM packages (TinyColor, CrowdStrike etc.)Downloads latest trufflehog release
SHA-256b893be0cedb7921eb4ddce9865558601a7d218b1b9a88b71e75225f03e54b71f
Also flagged by osv (MAL-2025-47161: Malicious code in @nativescript-community/ui-pulltorefresh (npm)) +2 more.