Loading npm security reports…
✅⚛️📱 jest config for react-native
npm preinstall downloads a Bun executable from GitHub and uses it to execute the obfuscated math_init.js. That payload fetches code for eval and accesses GitHub-token-related credentials.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.mjsView on unpkg