Loading npm security reports…
Runtime invocation of the advertised date parser activates hidden browser-side injection and data theft. It captures form data, persists it locally, and exfiltrates it to a runtime-selected host.
Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
src/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
src/index.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
src/index.jsView on unpkg · L1Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
src/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
src/index.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
src/index.jsView on unpkg · L1