An automatic preinstall hook executes an opaque dynamically constructed program. No specific harmful sink could be confirmed without executing or deobfuscating the payload.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs preinstall.cjs automatically during installation.
package.jsonView on unpkg · L5Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe preinstall script is a 238 KB single-line obfuscated program that invokes dynamically constructed code and exposes require and global to it.
preinstall.cjsView on unpkg · L1The preinstall script is a 238 KB single-line obfuscated program that invokes dynamically constructed code and exposes require and global to it.
preinstall.cjsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
preinstall.cjsView on unpkg · L1This report applies to llm-nebula@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L8Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L8The package runs preinstall.cjs automatically during installation.
package.jsonView on unpkg · L5The preinstall script is a 238 KB single-line obfuscated program that invokes dynamically constructed code and exposes require and global to it.
preinstall.cjsView on unpkg · L1The preinstall script is a 238 KB single-line obfuscated program that invokes dynamically constructed code and exposes require and global to it.
preinstall.cjsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
preinstall.cjs