Loading npm security reports…
core runtime
Importing the package triggers an asynchronous bootstrap without an explicit API call. It retrieves a remote platform payload (or DNS-delivered fallback), writes and executes it from temporary storage.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27