Opening index.html runs an obfuscated browser redirector. It obtains and decrypts a remote destination before redirecting the visitor.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe script decodes data, uses AES-CTR decryption, and converts the result into a URL.
index.htmlView on unpkg · L183The script decodes data, uses AES-CTR decryption, and converts the result into a URL.
index.htmlView on unpkg · L183The script resolves a remote host and replaces the browser location with that result.
index.htmlView on unpkg · L183The page loads a third-party Turnstile script and presents a Cloudflare-style challenge.
index.htmlView on unpkg · L10The manifest exposes an HTML file containing a large deliberately obfuscated script.
package.jsonView on unpkg · L1This report applies to @worrisome/aaaa@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
The page loads a third-party Turnstile script and presents a Cloudflare-style challenge.
index.htmlView on unpkg · L10A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182The script decodes data, uses AES-CTR decryption, and converts the result into a URL.
index.htmlView on unpkg · L183The script decodes data, uses AES-CTR decryption, and converts the result into a URL.
index.htmlView on unpkg · L183The script resolves a remote host and replaces the browser location with that result.
index.htmlView on unpkg · L183The manifest exposes an HTML file containing a large deliberately obfuscated script.
package.jsonView on unpkg · L1