Core JavaScript utilities for Node.js
The automatic install hook attempts system-data reporting and encrypted remote Python execution. Implementation defects may prevent the attempted attack from succeeding.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs init.js after installation.
package.jsonView on unpkg · L8Source file is highly similar to a previously finalized malicious package; route for source-aware review.
init.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
init.jsView on unpkginit.js targets an external server and a cache under the user's home directory.
init.jsView on unpkg · L16The install hook attempts to report the hostname, username and system details.
init.jsView on unpkg · L113It downloads an encrypted payload from /e, decrypts it and checks for TelemetrySender.
init.jsView on unpkg · L125This report applies to core-js-gnz@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L8package.json automatically runs init.js after installation.
package.jsonView on unpkg · L8init.js targets an external server and a cache under the user's home directory.
init.jsView on unpkg · L16The install hook attempts to report the hostname, username and system details.
init.jsView on unpkg · L113It downloads an encrypted payload from /e, decrypts it and checks for TelemetrySender.
init.jsView on unpkg · L125Source file is highly similar to a previously finalized malicious package; route for source-aware review.
init.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
init.jsView on unpkg