OpenSSF/OSV advisory MAL-2026-16367 confirms this npm version as malicious. The package was found to contain malicious code or consuming dependency that contains malicious code
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
bin/repl.jsView on unpkg · L2Package source references dynamic require/import behavior.
bin/repl.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
This report applies to math-universe@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
bin/repl.jsView on unpkg · L2Package source references dynamic require/import behavior.
bin/repl.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/browser/mathbase.jsView on unpkg