No confirmed exfiltration, persistence, or install-time attack was found. Obfuscated runtime code remains an unresolved risk when the REPL or browser bundle is used.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
bin/repl.jsView on unpkg · L2Package source references dynamic require/import behavior.
bin/repl.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/browser/mathbase.jsView on unpkgThe manifest exposes CommonJS, ESM, and browser runtime entry points.
package.jsonView on unpkg · L98This report applies to mathsbase@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
bin/repl.jsView on unpkg · L2Package source references dynamic require/import behavior.
bin/repl.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/browser/mathbase.jsView on unpkgThe manifest exposes CommonJS, ESM, and browser runtime entry points.
package.jsonView on unpkg · L98