MCP
Running the accessor-mcp bin loads an obfuscated loader that refuses analysis and then decrypts and executes a hidden script embedded in the package.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
accessor.cjsView on unpkg · L2accessor.cjs is obfuscated, loads module, path, zlib, and crypto through a string decoder, and exits when an inspector or debug-like process flags are present.
accessor.cjsView on unpkg · L3On startup it decrypts the embedded globalThis.__AP blob, inflates it, deletes those globals, and compiles the result with Module as the running file.
accessor.cjsView on unpkg · L2On startup it decrypts the embedded globalThis.__AP blob, inflates it, deletes those globals, and compiles the result with Module as the running file.
accessor.cjsView on unpkg · L3On startup it decrypts the embedded globalThis.__AP blob, inflates it, deletes those globals, and compiles the result with Module as the running file.
accessor.cjsView on unpkg · L3Package source references dynamic require/import behavior.
accessor.cjsView on unpkg · L2The package bin accessor-mcp points at accessor.cjs and declares no install lifecycle scripts.
package.jsonView on unpkg · L1This report applies to accessor-mcp@0.3.9.
See version security history for other recorded verdicts.
Evidence last updated: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
accessor.cjsView on unpkg · L2accessor.cjs is obfuscated, loads module, path, zlib, and crypto through a string decoder, and exits when an inspector or debug-like process flags are present.
accessor.cjsView on unpkg · L3On startup it decrypts the embedded globalThis.__AP blob, inflates it, deletes those globals, and compiles the result with Module as the running file.
accessor.cjsView on unpkg · L2On startup it decrypts the embedded globalThis.__AP blob, inflates it, deletes those globals, and compiles the result with Module as the running file.
accessor.cjsView on unpkg · L3On startup it decrypts the embedded globalThis.__AP blob, inflates it, deletes those globals, and compiles the result with Module as the running file.
accessor.cjsView on unpkg · L3Package source references dynamic require/import behavior.
accessor.cjsView on unpkg · L2The package bin accessor-mcp points at accessor.cjs and declares no install lifecycle scripts.
package.jsonView on unpkg · L1