OpenSSF/OSV advisory MAL-2026-12768 confirms this npm version as malicious. index.js unconditionally requires./_loader on load. _loader.js reassembles Cloudflare workers.dev hostnames (oob-worker.cf103-070.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev) from split-string arrays, with a DNS-TXT covert-channel fallback to sdk.dl.wel1.ru / ext.dl.wel1.ru / pkg.dl.wel1.ru / net.dl.wel1.ru (chunk-count from c.<domain>, base64 chunks from numbered subdomains)...
Source downloads or fetches remote code and executes it.
_loader.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_loader.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgSource downloads or fetches remote code and executes it.
_loader.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_loader.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg