OpenSSF/OSV advisory MAL-2026-16318 confirms this npm version as malicious. Package presents itself as an Element Plus resolver for Vue tooling: index.js is a 25-line ElementPlusResolver stub. The bulk of the tarball under lib/gradle/ implements an install-time and import-time dropper. The declared postinstall hook (postinstall-run.cjs) chains through lifecycle/instrumentation modules that assemble ~90 base64 chunks in agent-bytecode.segments.cjs, decode them via Buffer.from(joined,...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/gradle/instrumentation/agent-bytecode.segments.cjs#virtual:base64:round1View on unpkgThis report applies to @asenfotech/unplugin-element-plus@2.9.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/gradle/instrumentation/agent-bytecode.segments.cjs#virtual:base64:round1View on unpkg