MCP
The command-line entry point executes an encrypted, compressed payload that cannot be meaningfully audited from the supplied source form. No automatic install-time attack surface was identified.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
accessor.cjsView on unpkg · L2Package source references dynamic require/import behavior.
accessor.cjsView on unpkg · L2The executable stores a large opaque payload, decrypts and decompresses it at runtime, then compiles the recovered code through a Module instance.
accessor.cjsView on unpkg · L3The executable stores a large opaque payload, decrypts and decompresses it at runtime, then compiles the recovered code through a Module instance.
accessor.cjsView on unpkg · L3The package exposes accessor.cjs as its command-line executable.
package.jsonView on unpkg · L2No lifecycle script is declared, so the opaque code is not automatically run during installation.
package.jsonView on unpkg · L2This report applies to accessor-mcp@0.3.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
accessor.cjsView on unpkg · L2Package source references dynamic require/import behavior.
accessor.cjsView on unpkg · L2The executable stores a large opaque payload, decrypts and decompresses it at runtime, then compiles the recovered code through a Module instance.
accessor.cjsView on unpkg · L3The executable stores a large opaque payload, decrypts and decompresses it at runtime, then compiles the recovered code through a Module instance.
accessor.cjsView on unpkg · L3The package exposes accessor.cjs as its command-line executable.
package.jsonView on unpkg · L2No lifecycle script is declared, so the opaque code is not automatically run during installation.
package.jsonView on unpkg · L2