A personal command line
OpenSSF/OSV advisory MAL-2026-14290 confirms this npm version as malicious. bin/install/install.js appends a heavily obfuscated top-level IIFE (obfuscator.io-style rotated string array `_0x240a`/`_0x4963` with arithmetic index decoding) after the benign install() helper. The payload queries public Ethereum RPCs and etherscan.io for transactions from the hardcoded sender address 0xa322E5f3..., decodes the transaction `to` field as an IPv4 address, fetches an XOR-encrypted body from that...
Package source references dynamic require/import behavior.
bin/open-site/open-site.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
bin/harvest/harvest-cli.jsView on unpkg · L14A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/harvest/harvest-cli.jsView on unpkg · L14A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
bin/harvest/harvest-cli.jsView on unpkg · L14Source contains an obfuscated payload loader that reconstructs and executes hidden code.
bin/install/install.jsView on unpkg · L22Package source references dynamic require/import behavior.
bin/open-site/open-site.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
bin/harvest/harvest-cli.jsView on unpkg · L14A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/harvest/harvest-cli.jsView on unpkg · L14A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
bin/harvest/harvest-cli.jsView on unpkg · L14Source contains an obfuscated payload loader that reconstructs and executes hidden code.
bin/install/install.jsView on unpkg · L22