No confirmed malicious attack surface is present in shipped source. The only lifecycle hook points to a missing file, causing install failure rather than executing packaged payload code.
Static reason
One or more suspicious static signals were detected.
Trigger
npm install attempts package.json postinstall
Impact
install may fail; no observed credential, file, network, persistence, or destructive behavior
Mechanism
missing postinstall script target; runtime library is pure math
Rationale
Static inspection found a suspicious lifecycle declaration and misleading README claim, but the referenced script is absent and the shipped entrypoint contains only package-aligned math code. No exfiltration, dynamic execution, persistence, destructive action, or AI-agent control-surface mutation was found.
Evidence
package.jsondist/index.jsdist/index.d.tsREADME.mdscripts/install-check.cjs
Network endpoints2
www.zscdao.help/config/stake-math-sync.jsongithub.com/zscdao/kelly.git