Opening the package's HTML entrypoint displays a fake security challenge. Completing it activates obfuscated code that obtains and decrypts a remote redirect target, then forwards browser query parameters.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L226A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe callback POSTs to a concealed endpoint, decrypts a server-provided URL, copies current query parameters, and redirects the browser.
index.htmlView on unpkg · L227The callback POSTs to a concealed endpoint, decrypts a server-provided URL, copies current query parameters, and redirects the browser.
index.htmlView on unpkg · L227Manifest exposes only an HTML page as the package entrypoint.
package.jsonView on unpkg · L2The callback POSTs to a concealed endpoint, decrypts a server-provided URL, copies current query parameters, and redirects the browser.
index.htmlView on unpkg · L227The callback POSTs to a concealed endpoint, decrypts a server-provided URL, copies current query parameters, and redirects the browser.
index.htmlView on unpkg · L227Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L226A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgManifest exposes only an HTML page as the package entrypoint.
package.jsonView on unpkg · L2