interface elements
Installing or importing the package fetches a platform-specific binary payload, writes it to a temp directory, makes it executable, and launches it detached. DNS TXT records provide a fallback payload channel.
Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27