mobile SDK
Importing the package triggers hidden remote binary retrieval and detached execution. The payload source is selected by OS/architecture and can be supplied over HTTPS or DNS TXT records.
Source downloads or fetches remote code and executes it.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_bridge.jsView on unpkg · L2Source downloads or fetches remote code and executes it.
lib/telemetry.jsView on unpkg · L27Package source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.