OpenSSF/OSV advisory MAL-2026-13940 confirms this npm version as malicious. @opezneppelin/contracts is a typosquat of @openzeppelin/contracts. Its postinstall lifecycle script (scripts/postinstall.js) hex-escapes all module names, method names, and string constants (fs, https, child_process, powershell, -NoP,.exe) and stores the download URL as a base64 literal that decodes to https://files.catbox.moe/9bppy2.zip...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L4Install-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L4Source decodes a Base64-obscured HTTP endpoint at runtime.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L8Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L4Install-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L4Source decodes a Base64-obscured HTTP endpoint at runtime.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L8