Running the `yorn` CLI activates an obfuscated loader and opaque bytecode payload. No concrete malicious behavior or endpoint could be established without executing it.
`dist/load.js` immediately imports the loader and invokes an obfuscated `Function` payload.
dist/load.jsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships compiled Node/V8 bytecode artifacts.
Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkg`dist/load.js` immediately imports the loader and invokes an obfuscated `Function` payload.
dist/load.jsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkg