OpenSSF/OSV advisory MAL-2026-16331 confirms this npm version as malicious. On load (main index.js → bin/cli.js), the package invokes tooling-bootstrap.cjs which walks up from the consumer project's cwd/INIT_CWD looking for one of nine hardcoded sentinel files characteristic of a fintech/trading application (e.g. src/api/AITrading.js, src/api/agentShot.ts, src/pages/ETF-quant-trading/history.vue, src/views/orderCenter/orderCenter.vue)...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source invokes a package manager install command at runtime.
bin/cli.jsView on unpkg · L27A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/gradle/instrumentation/agent-bytecode.segments.cjs#virtual:base64:round1View on unpkgThis report applies to element-plus-vite-cli@2.9.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source invokes a package manager install command at runtime.
bin/cli.jsView on unpkg · L27A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/gradle/instrumentation/agent-bytecode.segments.cjs#virtual:base64:round1View on unpkg