Headless agent package for controlling 3dverse rendering sessions programmatically (Node.js and browser compatible)
No confirmed attack surface was identified. Remote core loading, authentication, and playback file access support caller-invoked rendering and ingestion operations.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/index.cjsView on unpkg · L2394A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.cjsView on unpkgPackage source references dynamic require/import behavior.
dist/index.cjsView on unpkg · L8Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.mjsView on unpkgThis report applies to @3dverse/livelink-agent@0.5.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/index.cjsView on unpkg · L8A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.mjsView on unpkgSource fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/index.cjsView on unpkg · L2394