Importing the package loads extensively obfuscated code containing shell execution and network requests. These establish unresolved risk, but the inspected source does not establish a specific malicious command or recipient.
Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
lib/config.jsView on unpkgThis report applies to hardhat-jsx@2.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
lib/config.jsView on unpkg