Loading npm security reports…
This is a high-performance web framework for Node.js, offering the fastest speeds in the ecosystem with minimal overhead.
Calling getPlugin downloads attacker-controlled JSON from a hard-coded server and executes its credits field as JavaScript. The evaluated payload receives privileged Node globals.
Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkg