Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-17336 confirms this npm version as malicious. The package ships `code.png` alongside `index.js` and exports a function `imageToCode` that reads a length-prefixed byte stream from the first pixel row of the PNG and passes the decoded string to `Function(...)()`, an eval-equivalent sink. The executable content is hidden inside an image asset rather than present as readable source, so the code that will run cannot be seen by inspecting the npm tarball...
This report applies to @redman89405/my-module@1.1.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .