OpenSSF/OSV advisory MAL-2026-16156 confirms this npm version as malicious. get-power impersonates ljharb's get-proto utility (package.json declares author 'Jordan Harband <ljharb@gmail.com>' and homepage github.com/ljharb/get-power) while mirroring get-proto's file layout as cover. On require(), index.js base64-decodes two bundled files disguised as sourcemaps (parse.ts.map, init.ts.map) into parsetmp.js and config.js, require()s parsetmp.js, then fs.unlink()s all four files to erase...
Package source references dynamic require/import behavior.
Object.getPrototypeOf.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis report applies to get-power@1.0.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references dynamic require/import behavior.
Object.getPrototypeOf.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkg