OpenSSF/OSV advisory MAL-2026-13279 confirms this npm version as malicious. On require of the package's main, _platform.js downloads an opaque platform-specific binary from obfuscated Cloudflare Workers subdomains (hostnames assembled from split string fragments such as ['oob-worke','r.cf102-baf.workers','.d','ev']) with a DNS-TXT covert-channel fallback that reassembles a base64 payload from numbered TXT records under c.*.dl.wel1.ru...
Source downloads or fetches remote code and executes it.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_platform.jsView on unpkg · L6Source downloads or fetches remote code and executes it.
lib/telemetry.jsView on unpkg · L27Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgPackage source references weak cryptographic algorithms.
lib/telemetry.jsView on unpkg · L27A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_platform.jsView on unpkg · L6