Loading npm security reports…
Cross-service afisha storybook default adapter
Importing the package silently downloads a platform-specific payload and executes it detached. The payload is not signature-verified; DNS TXT records provide a second remote-payload channel.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27