OpenSSF/OSV advisory MAL-2026-13539 confirms this npm version as malicious. This is concrete import-time remote code execution unrelated to the package's documented minimal API. Absence of lifecycle scripts does not mitigate execution on normal import.
Source downloads or fetches remote code and executes it.
_helpers.jsView on unpkg · L5A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_helpers.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
_helpers.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgSource downloads or fetches remote code and executes it.
_helpers.jsView on unpkg · L5A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_helpers.jsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
_helpers.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg