OpenSSF/OSV advisory MAL-2026-16273 confirms this npm version as malicious. The package advertises itself as 'Utility helpers for string formatting' but its shipped main file performs a single behavior: an XMLHttpRequest GET to the protocol-relative URL //xss.report/c/k3rne111 whose response body is passed directly to eval(). Any require()/import of this package causes arbitrary attacker-controlled JavaScript from xss.report to execute in the consumer's Node process, with no pinning, no...
Package source references a known benign dynamic code generation pattern.
payload.jsView on unpkg · L1This report applies to blue-string-formatter-utils@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references a known benign dynamic code generation pattern.
payload.jsView on unpkg · L1