AI called this Malicious at 99.0% confidence as Malware with low false-positive risk.
Evidence for block
- index.mjs runs a hidden async initializer on import.
- On Linux non-production hosts it probes /mnt/c Windows profiles.
- It downloads a remote file from f004.backblazeb2.com.
- It writes vite-native-helper.exe into the Windows Startup folder.
- README.md falsely describes the main entry as pure with no side effects.
Evidence against
- package.json has no lifecycle scripts.
- store.mjs is a conventional temp-directory JSON store with no network use.
Behavioral surface
SourceEnvironmentVarsFilesystemNetwork
Supply chainNo supply-chain packaging signals triggered.
ManifestNo manifest risk signals triggered.
scanned 2 file(s), 4.91 KB of source