Opening the package's HTML entry point runs an obfuscated browser redirect flow. It uses a CAPTCHA-looking screen and conceals the final destination behind encrypted data and policy fetches.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML runs a Turnstile callback that invokes a redirect function.
index.htmlView on unpkg · L176The manifest makes an HTML document the package entry point.
package.jsonView on unpkg · L1This report applies to luftzxyuiwgbgsp@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML runs a Turnstile callback that invokes a redirect function.
index.htmlView on unpkg · L176The manifest makes an HTML document the package entry point.
package.jsonView on unpkg · L1