Loading npm security reports…
React components
Importing the package triggers a concealed bootstrap that downloads and executes a native payload. The payload is written under a temporary directory, made executable on non-Windows systems, detached, and deleted shortly afterward.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27