Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-13388 confirms this npm version as malicious. The bundled main (dist/index.js) executes an eval(atob(...)) blob at module top level, so any Node-side require() of the package (SSR, tests, Next.js server rendering) runs it...