OpenSSF/OSV advisory MAL-2026-13391 confirms this npm version as malicious. No a static rule or traced code paths flagged malicious behavior in this package. No lifecycle hooks fetching or executing remote content, no credential or environment scraping, no hardcoded exfiltration endpoints, no silent-relay of caller data, and no persistence mechanisms were observed.
Package source references a known benign dynamic code generation pattern.
index.cjs.jsView on unpkg · L1241A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.esm.js#virtual:base64:round1View on unpkg · L1Package source references a known benign dynamic code generation pattern.
index.cjs.jsView on unpkg · L1241A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.esm.js#virtual:base64:round1View on unpkg · L1