Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-17506 confirms this npm version as malicious. The package's declared main entry index.js unconditionally requires./lib/config, a 4,499,968-byte obfuscator.io-packed file (26,234-entry string array, hex-renamed identifiers, control-flow flattening, top-level IIFE) that executes as soon as any consumer runs `require('hardhat-ftp')`...
This report applies to hardhat-ftp@2.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.