Loading npm security reports…
An inert browser script can lock a page behind a deceptive subscription-expired overlay when embedded. It is not reachable through the package's declared npm entrypoint.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/chunk-YR2M2MZ9.jsView on unpkg · L1The browser payload creates a full-screen, highest-layer overlay.
chunk-original.jsView on unpkg · L26It disables scrolling, page pointer input, and keyboard events.
chunk-original.jsView on unpkg · L48It removes its own script element after modifying the page.
chunk-original.jsView on unpkg · L61Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/chunk-YR2M2MZ9.jsView on unpkg · L1The browser payload creates a full-screen, highest-layer overlay.
chunk-original.jsView on unpkg · L26It disables scrolling, page pointer input, and keyboard events.
chunk-original.jsView on unpkg · L48It removes its own script element after modifying the page.
chunk-original.jsView on unpkg · L61