Pluggable bigops insite interface
Importing the advertised package triggers a hidden downloader. It retrieves an unverified platform-specific payload and executes it detached from a temporary directory.
Source downloads or fetches remote code and executes it.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
setup.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.jsView on unpkgSource downloads or fetches remote code and executes it.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
setup.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.jsView on unpkg