OpenSSF/OSV advisory MAL-2026-13500 confirms this npm version as malicious. This is a concrete, import-triggered remote payload execution chain with stealth-oriented temporary paths and detached execution. The absent npm lifecycle hook does not mitigate execution on normal package use.
Source downloads or fetches remote code and executes it.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_platform.jsView on unpkg · L2Source downloads or fetches remote code and executes it.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_platform.jsView on unpkg · L2