Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16318 confirms this npm version as malicious.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource decodes a Base64-obscured HTTP endpoint at runtime.
tooling-bootstrap.cjsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
tooling-bootstrap.cjs#virtual:base64:round1View on unpkgThis report applies to @asenfotech/unplugin-element-plus@2.9.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource decodes a Base64-obscured HTTP endpoint at runtime.
tooling-bootstrap.cjsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
tooling-bootstrap.cjs#virtual:base64:round1View on unpkg