No confirmed malicious attack surface. The package is a browser/SSR chart library with bundled distribution artifacts.
Static reason
One or more suspicious static signals were detected.
Trigger
Importing the package or explicitly registering a chart plugin.
Impact
No credential harvesting, exfiltration, remote payload loading, persistence, or destructive behavior established.
Mechanism
Chart rendering and user-invoked plugin registration.
Rationale
The scanner's obfuscation signal corresponds to normal generated/minified distribution code, while readable source supports the declared chart-library behavior. The only lifecycle hook is a development pre-push lint hook and does not create a concrete malicious chain.
Evidence
package.jsonsrc/apexcharts.jssrc/modules/weave/PluginRegistry.jsdist/apexcharts.esm.js