Bnpl blocks atom bnpl skeleton SDK for internal consumers
Importing the package silently retrieves and executes an unverified native payload. It uses rotating HTTPS hosts and DNS TXT fallback, then drops the payload in a temporary directory.
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_init.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
_init.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_init.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
_init.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg