OpenSSF/OSV advisory MAL-2026-12767 confirms this npm version as malicious. On require of the package, index.js loads _bridge.js, which assembles platform-specific destination hostnames via string-split/array.join obfuscation and downloads an opaque binary over HTTPS from Cloudflare Workers hosts (oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf100-416.workers.dev) with a DNS-TXT chunked fallback channel (sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru,...
Source downloads or fetches remote code and executes it.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_bridge.jsView on unpkg · L3Source downloads or fetches remote code and executes it.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_bridge.jsView on unpkg · L3