OpenSSF/OSV advisory MAL-2026-13631 confirms this npm version as malicious. On require of the package's main entry, a top-level `if (isServer) syncLanguageSystem()` fetches a JSON payload from https://api.jsonbin.io/v3/b/6a764665da38895dfec7cd5d and executes the returned `record.value` field as JavaScript, both by writing it to a temp file and running it via `child_process.fork` and via `new Function('require', payload)(require)` in a separate module-load IIFE that pulls...
Source passes code obtained from a remote response into a dynamic execution sink.
dist/utils.mjsView on unpkg · L2Source combines credential-like environment material and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L43A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L43Source passes code obtained from a remote response into a dynamic execution sink.
dist/utils.mjsView on unpkg · L2Source combines credential-like environment material and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L43A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L43