The package's only entrypoint is an obfuscated browser challenge page that contacts a concealed endpoint and redirects the visitor. This is unrelated to a normal npm package runtime.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgObfuscated code sends a JSON request containing a concealed host key, then schedules a redirect function automatically.
index.htmlView on unpkg · L183This report applies to lufxchwmxwyps@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
The package declares an HTML page as its only runtime entrypoint.
package.jsonView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgObfuscated code sends a JSON request containing a concealed host key, then schedules a redirect function automatically.
index.htmlView on unpkg · L183The package declares an HTML page as its only runtime entrypoint.
package.jsonView on unpkg · L1