The browser entrypoint presents a Turnstile challenge and then automatically follows concealed redirect logic. No confirmed credential theft or destructive action was identified.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe entrypoint loads Cloudflare Turnstile and invokes a redirect callback after completion.
index.htmlView on unpkg · L178The entrypoint contains heavily obfuscated code with an encoded host value and schedules redirectToHost.
index.htmlView on unpkg · L183The package declares index.html as its only main entrypoint.
package.jsonView on unpkg · L2This report applies to cloudndmcedu@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe entrypoint loads Cloudflare Turnstile and invokes a redirect callback after completion.
index.htmlView on unpkg · L178The entrypoint contains heavily obfuscated code with an encoded host value and schedules redirectToHost.
index.htmlView on unpkg · L183The package declares index.html as its only main entrypoint.
package.jsonView on unpkg · L2