Loading npm security reports…
🧬 graphql config and checks
npm install runs an obfuscated payload through Bun. The payload includes remote code execution and GitHub credential-harvesting logic.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.mjsView on unpkg