Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-13630 confirms this npm version as malicious. This package impersonates the @rbxts/services Roblox typings library and re-exports its public API in index.js as cover. Its postinstall script (scripts/postinstall.js) is gated to win32 and uses \x hex escapes to hide the strings 'child_process', 'spawn', 'powershell', and related identifiers...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource decodes a Base64-obscured HTTP endpoint at runtime.
scripts/postinstall.jsPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource decodes a Base64-obscured HTTP endpoint at runtime.
scripts/postinstall.jsView on unpkg · L6