Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-17322 confirms this npm version as malicious. Package ships a single ~138 KB browser script whose entire body is an RC4-encrypted base64 blob decoded at runtime by an inline RC4 routine (`_zc`) with a DJB2 helper (`_zh`) and a key reconstructed by XORing a numeric array with 1410^714...
This report applies to contoso-login-sim-loader@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .