js tokens array
Importing the main entry immediately retrieves and executes code controlled by a remote server. The fetched payload can run with the importing process's permissions.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgOn import, the package fetches a remote response and executes its token field with eval.
index.jsThe remote URL is hidden as character codes and resolves to https://access-token-delta.vercel.app/.
index.jsView on unpkg · L3Package source references a known benign dynamic code generation pattern.
index.jsView on unpkg · L11Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgOn import, the package fetches a remote response and executes its token field with eval.
index.jsView on unpkg · L10The remote URL is hidden as character codes and resolves to https://access-token-delta.vercel.app/.
index.jsView on unpkg · L3Package source references a known benign dynamic code generation pattern.
index.jsView on unpkg · L11