系统级 mailbox/hub 同步 daemon (Node)
No confirmed attack was established. The package has no install hook, while several modules on the import path are obfuscated and could not be fully audited within the citation limit.
Package source references dynamic require/import behavior.
dist/llm/upstream.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/llm/traceEnvelope.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/selfUpdate/windowsUpdater.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/selfUpdate/bootstrap.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/daemon/systemdNotifier.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/selfUpdate/releaseBinary.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/selfUpdate/transaction.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/selfUpdate/unixController.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/selfUpdate/windowsController.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/private/privateRuntimeSmokeOptions.jsView on unpkgThis report applies to @evomap/evolver-proxy@2.0.37.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/llm/upstream.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/selfUpdate/windowsUpdater.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/selfUpdate/bootstrap.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/daemon/systemdNotifier.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/selfUpdate/releaseBinary.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/selfUpdate/transaction.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/selfUpdate/unixController.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/selfUpdate/windowsController.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/private/privateRuntimeSmokeOptions.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/llm/traceEnvelope.jsView on unpkg · L1