OpenSSF/OSV advisory MAL-2026-16200 confirms this npm version as malicious. @zaka13/thing@1.0.0 ships the same disguised in-browser proxy kit as webpackbootstrap5 and webpackbootstrapscripts by the same publisher (zaka13). Its YXBp.js loader matches those packages' index-z2b7r4.js (same sha256): it XOR-decodes endpoints with a fixed key, injects remote scripts from https://dyingefforlessefforlessours.com, and boots a Scramjet/wisp WebSocket proxy routing traffic through operator relays...
Package source references dynamic require/import behavior.
bG9scmF0aW9u/ejRrc2F0.jsView on unpkg · L1This report applies to @zaka13/thing@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
logo-b2b3e4d75f89f6104a35c1c7a5972ddd1be2cf72.svgView on unpkgPackage source references dynamic require/import behavior.
bG9scmF0aW9u/ejRrc2F0.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
logo-b2b3e4d75f89f6104a35c1c7a5972ddd1be2cf72.svgView on unpkg