Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16146 confirms this npm version as malicious. The package's preinstall script (build.js) assembles a remote hostname from split string fragments that resolve to dawn-salad-18c7.mikhail-nab.workers.dev, base64-encodes the full process.env, and POSTs it to that endpoint on npm install...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThis report applies to @aiwfm/communitywfm.scripts.api@28.1.28.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg