MCP
The command-line entrypoint carries an opaque encrypted payload and executes its decoded contents. No concrete network, credential, or file attack could be established without executing the concealed payload.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
accessor.cjsView on unpkg · L2Package source references dynamic require/import behavior.
accessor.cjsView on unpkg · L2The command file begins with a multi-megabyte encoded payload rather than readable implementation.
accessor.cjsView on unpkg · L1This report applies to accessor-mcp@0.3.6.
See version security history for other recorded verdicts.
Evidence last updated: .
The entrypoint decrypts and inflates concealed code, then loads it as a module at runtime.
accessor.cjsView on unpkg · L3The entrypoint decrypts and inflates concealed code, then loads it as a module at runtime.
accessor.cjsView on unpkg · L3The manifest exposes accessor.cjs as the command-line entrypoint.
package.jsonView on unpkg · L2Source contains an obfuscated payload loader that reconstructs and executes hidden code.
accessor.cjsView on unpkg · L2Package source references dynamic require/import behavior.
accessor.cjsView on unpkg · L2The command file begins with a multi-megabyte encoded payload rather than readable implementation.
accessor.cjsView on unpkg · L1The entrypoint decrypts and inflates concealed code, then loads it as a module at runtime.
accessor.cjsView on unpkg · L3The entrypoint decrypts and inflates concealed code, then loads it as a module at runtime.
accessor.cjsView on unpkg · L3The manifest exposes accessor.cjs as the command-line entrypoint.
package.jsonView on unpkg · L2