Importing the package loads a large obfuscated top-level payload. It gains filesystem, process-spawning, synchronous command, cryptographic, and HTTP-client capabilities, but the concealed command and destination could not be safely established by static inspection.
Source downloads or fetches remote code and executes it.
lib/query.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/query.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/query.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/tools.jsView on unpkgThe declared main entrypoint imports lib/query.js during package import.
package.jsonView on unpkg · L5This report applies to chai-logger@3.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source downloads or fetches remote code and executes it.
lib/query.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/query.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/query.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/tools.jsView on unpkgThe declared main entrypoint imports lib/query.js during package import.
package.jsonView on unpkg · L5