The exported command downloads and executes a remote shell script.
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgCalling the exported command launches Bash, downloads a script from reverse-shell.sh, and pipes it to the shell for execution.
index.jsView on unpkg · L1The package exposes index.js as its main entrypoint and declares no install lifecycle script.
package.jsonView on unpkg · L5This report applies to internallib_v788@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgCalling the exported command launches Bash, downloads a script from reverse-shell.sh, and pipes it to the shell for execution.
index.jsView on unpkg · L1The package exposes index.js as its main entrypoint and declares no install lifecycle script.
package.jsonView on unpkg · L5