CLI to create multi-package Lerna projects with TypeScript and React
npm preinstall unconditionally launches an obfuscated payload. The loader downloads Bun when absent and executes the payload, which contains credential/token collection and network-upload code.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
setup.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.mjsView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Package source references dynamic require/import behavior.
bin/webpack.jsView on unpkg · L2Package source references weak cryptographic algorithms.
src/vite/plugins/shared-dependencies-plugin/shared-dependencies-plugin.tsView on unpkg · L51Package source invokes a package manager install command at runtime.
dist/cli/commands/clean.jsView on unpkg · L63Package defines install-time lifecycle scripts.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
setup.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.mjsView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Package source references dynamic require/import behavior.
bin/webpack.jsView on unpkg · L2Package source references weak cryptographic algorithms.
src/vite/plugins/shared-dependencies-plugin/shared-dependencies-plugin.tsView on unpkg · L51Package source invokes a package manager install command at runtime.
dist/cli/commands/clean.jsView on unpkg · L63