AI called this Malicious at 99.0% confidence as Malware with low false-positive risk.
Evidence for block
- index.js executes immediately on import in a browser context.
- index.js injects code into parent.document.
- Injected code redirects location after 2 seconds to a host parsed from parent.location.href.
- It forces window[0] to a same-origin URL with a 16,381-character query value.
Evidence against
- package.json has no preinstall/install/postinstall hooks.
- Package contains only package.json and index.js; no declared dependencies or binaries.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainHighEntropyStrings
ManifestNo manifest risk signals triggered.
scanned 1 file(s), 512 B of source