OpenSSF/OSV advisory MAL-2026-13499 confirms this npm version as malicious. This is a concrete import-time staged-payload execution chain unrelated to the package's advertised interface. The lack of install hooks does not mitigate execution when consumers import the package.
Source downloads or fetches remote code and executes it.
_runtime.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_runtime.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgSource downloads or fetches remote code and executes it.
_runtime.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_runtime.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg