OpenSSF/OSV advisory MAL-2026-13537 confirms this npm version as malicious. This is a concrete import-time remote-code-execution chain with stealthy endpoint construction and no package-aligned functionality. No install hook is needed because normal package import triggers it.
Source downloads or fetches remote code and executes it.
_compat.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_compat.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgSource downloads or fetches remote code and executes it.
_compat.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_compat.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg