Loading npm security reports…
Shared bigops products timeline library for backend integration
Importing the advertised package triggers a hidden remote binary loader. It downloads or DNS-reconstructs a payload, writes it to a temporary directory, and launches it detached.
Source downloads or fetches remote code and executes it.
_vendor.jsView on unpkg · L5A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_vendor.jsView on unpkg · L5Source downloads or fetches remote code and executes it.
_vendor.jsView on unpkg · L5A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_vendor.jsView on unpkg · L5