The user-invoked yorn bin executes an obfuscated loader and opaque V8 bytecode. No specific malicious action is attributable without inspectable payload source.
Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkgThe executable bin is an obfuscated dynamic Function loader.
dist/load.cjsView on unpkg · L2The loader decompresses encoded content and dynamically constructs another function; its 15 MB bytecode payload cannot be source-reviewed.
dist/load.cjsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
dist/load.jsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
dist/skills/screenshot/scripts/take_screenshot.pyView on unpkgPackage ships high-entropy non-source blobs.
dist/skills/theme-factory/theme-showcase.pdfView on unpkgThe executable bin is an obfuscated dynamic Function loader.
dist/load.cjsView on unpkg · L2The loader decompresses encoded content and dynamically constructs another function; its 15 MB bytecode payload cannot be source-reviewed.
dist/load.cjsView on unpkg · L2