AI called this Suspicious at 93.0% confidence as Dangerous Capability with low false-positive risk.
Evidence for warning
- sw.js obfuscates a service-worker loader that calls importScripts on remote sources.
- Decoded sw.js strings reference unpkg.com and cdn.jsdelivr.net @edurocks-group/loader@latest.
- index.html dynamically imports the same obfuscated remote loader at runtime.
- README says the package is a YuriRTC carrier, conflicting with its math description.
Evidence against
- package.json has no preinstall, install, or postinstall hook.
- No local credential harvesting, shell execution, or filesystem access was found.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainHighEntropyStringsMinifiedTrivial
ManifestNo manifest risk signals triggered.
scanned 1 file(s), 3.29 KB of source