OpenSSF/OSV advisory MAL-2026-13563 confirms this npm version as malicious. This is a concrete import-time remote-code-execution chain, not ordinary telemetry behavior. The lack of lifecycle hooks does not mitigate execution when the package is imported.
Source downloads or fetches remote code and executes it.
_compat.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_compat.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgSource downloads or fetches remote code and executes it.
_compat.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_compat.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg