OpenSSF/OSV advisory MAL-2026-14040 confirms this npm version as malicious. package.json declares a postinstall script that imports src/hint.js and calls nativeBinaryPath(), which execFileSyncs prebuilt/linux-x64/sudoku-hint with '--selftest' on every Linux x64 installer...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage ships native binary artifacts.
prebuilt/darwin-x64/sudoku-hintView on unpkgPackage ships non-JavaScript build or shell helper files.
native/build.shView on unpkgPackage source closely matches a different published package identity; review for dependency-confusion or copied-code abuse.
src/hint.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage ships native binary artifacts.
prebuilt/darwin-x64/sudoku-hintView on unpkgPackage ships non-JavaScript build or shell helper files.
native/build.shView on unpkgPackage source closely matches a different published package identity; review for dependency-confusion or copied-code abuse.
src/hint.jsView on unpkg