OpenSSF/OSV advisory MAL-2026-13630 confirms this npm version as malicious. This package impersonates the @rbxts/services Roblox typings library and re-exports its public API in index.js as cover. Its postinstall script (scripts/postinstall.js) is gated to win32 and uses \x hex escapes to hide the strings 'child_process', 'spawn', 'powershell', and related identifiers...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L5Source decodes a Base64-obscured HTTP endpoint at runtime.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L9This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/postinstall.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L5Source decodes a Base64-obscured HTTP endpoint at runtime.
scripts/postinstall.js#virtual:normalized:round1View on unpkg · L9This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/postinstall.jsView on unpkg