OpenSSF/OSV advisory MAL-2026-16331 confirms this npm version as malicious.
Package source invokes a package manager install command at runtime.
bin/cli.jsView on unpkg · L27Source decodes a Base64-obscured HTTP endpoint at runtime.
tooling-bootstrap.cjsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
tooling-bootstrap.cjs#virtual:base64:round1View on unpkgThis report applies to element-plus-vite-cli@2.9.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source invokes a package manager install command at runtime.
bin/cli.jsView on unpkg · L27Source decodes a Base64-obscured HTTP endpoint at runtime.
tooling-bootstrap.cjsView on unpkg · L5A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
tooling-bootstrap.cjs#virtual:base64:round1View on unpkg