AI called this Suspicious at 90.0% confidence as Unknown with medium false-positive risk.
Evidence for block
- The public entrypoint exports a value sourced from an embedded encrypted database.
- The imported payload file is an 18,456-byte OpenSSL-encrypted, base64-encoded blob.
- No decryption, execution, network transmission, or stated package function explains exporting this payload.
Evidence against
- Root manifest has no preinstall, install, or postinstall hook.
- Inspected source contains no child-process use, dynamic evaluation, network client, credential harvesting, or file writes.
- The encrypted blob is read only when the package is imported; it is not executed by package code.
Behavioral surface
scanned 15 file(s), 7.78 KB of source, external domains: github.com