An automatic install hook contains an opaque staged payload. It decompresses hidden data, writes generated content, and starts a child process during installation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package registers an automatic preinstall hook that runs preinstall.cjs.
package.jsonView on unpkg · L8Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe preinstall file is a large, deliberately obfuscated Function payload that dynamically obtains module loading.
preinstall.cjsView on unpkg · L1The hook loads file, path, compression, and child-process modules, decompresses data, writes a generated file, and launches a child process.
preinstall.cjsView on unpkg · L1The hook loads file, path, compression, and child-process modules, decompresses data, writes a generated file, and launches a child process.
preinstall.cjsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
preinstall.cjsView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
nebula.jsView on unpkgThis report applies to api-nebula@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L8Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L8The package registers an automatic preinstall hook that runs preinstall.cjs.
package.jsonView on unpkg · L8The preinstall file is a large, deliberately obfuscated Function payload that dynamically obtains module loading.
preinstall.cjsView on unpkg · L1The hook loads file, path, compression, and child-process modules, decompresses data, writes a generated file, and launches a child process.
preinstall.cjsView on unpkg · L1The hook loads file, path, compression, and child-process modules, decompresses data, writes a generated file, and launches a child process.
Source fingerprint signature matches a known malicious package signature; route for source-aware review.
nebula.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
preinstall.cjsView on unpkg · L1