OpenSSF/OSV advisory MAL-2026-12743 confirms this npm version as malicious. On require of the package, index.js loads _helpers.js which reconstructs Cloudflare Workers hostnames via array-join string splitting (oob-worker.cf{99-9b3,101-adf,102-baf,103-070}.workers.dev), downloads a platform-specific binary, writes it to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmods 0755, and spawns it detached via /bin/sh -c or cmd.exe /c start...
Source downloads or fetches remote code and executes it.
_helpers.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_helpers.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgSource downloads or fetches remote code and executes it.
_helpers.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_helpers.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg