Loading npm security reports…
The Hyperliquid API SDK, written in TypeScript, supports all major JavaScript environments.
OpenSSF/OSV advisory MAL-2026-14042 confirms this npm version as malicious. package.json declares `inquirer` with a tarball URL pointing at registrynpmjs.to — a domain that typosquats the official npm registry (registry.npmjs.org). Running `npm install` fetches and installs whatever tarball is hosted at that attacker-controlled URL as a transitive dependency, delivering arbitrary code into the installer's node_modules on every install...
Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg · L61