Loading npm security reports…
structured logging
Importing the package silently retrieves an opaque native payload and executes it detached. It uses HTTPS mirrors with DNS-TXT payload fallback and a short cooldown stamp.
Source downloads or fetches remote code and executes it.
_support.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_support.jsView on unpkg · L4Source downloads or fetches remote code and executes it.
_support.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_support.jsView on unpkg · L4