OpenSSF/OSV advisory MAL-2026-13778 confirms this npm version as malicious. No static or traced indicators of supply-chain attack behavior were observed in this package version. No lifecycle scripts fetching or executing remote content, no credential or environment scraping, no hardcoded attacker network destinations, no silent-relay of caller-supplied data, and no persistence or backdoor mechanisms are present in the scanned files.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/install.js#virtual:normalized:round1View on unpkg · L27Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/install.js#virtual:normalized:round1View on unpkg · L27