🔧 repo config
Install-time remote code execution is confirmed. The preinstall bootstrap executes an opaque payload which can fetch and eval further code and handles GitHub credentials.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Package source references dynamic require/import behavior.
bin/ornikar-repo-config-postinstall.jsView on unpkg · L4Package ships non-JavaScript build or shell helper files.
bin/ornikar-prettier-fix.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Package source references dynamic require/import behavior.
bin/ornikar-repo-config-postinstall.jsView on unpkg · L4Package ships non-JavaScript build or shell helper files.
bin/ornikar-prettier-fix.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.mjsView on unpkg