Opening the HTML entry point in a browser runs an obfuscated challenge-and-redirect flow. The final destination is hidden in source.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page loads a Cloudflare challenge script and then fetches a policy redirect before navigating the browser.
index.htmlView on unpkg · L10The manifest makes an HTML file the package entry point.
package.jsonView on unpkg · L4This report applies to afhmxiewpsf@1.0.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page loads a Cloudflare challenge script and then fetches a policy redirect before navigating the browser.
index.htmlView on unpkg · L10The manifest makes an HTML file the package entry point.
package.jsonView on unpkg · L4