Headless agent package for controlling 3dverse rendering sessions programmatically (Node.js and browser compatible)
Static analysis completed at 0.0% confidence. No malicious behavior was detected; 14 low-signal pattern(s) were surfaced and cleared.
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/index.cjsView on unpkg · L2394A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.cjsView on unpkgPackage source references dynamic require/import behavior.
dist/index.cjsView on unpkg · L8Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.mjsView on unpkgThis report applies to @3dverse/livelink-agent@0.5.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/index.cjsView on unpkg · L8A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.mjsView on unpkgSource fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/index.cjsView on unpkg · L2394