Loading the published HTML in a browser presents a Turnstile challenge and then redirects to an obfuscated, dynamically resolved destination. No confirmed credential theft or local system mutation was identified.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML loads Cloudflare Turnstile and invokes a challenge redirect callback.
index.htmlView on unpkg · L9The HTML loads Cloudflare Turnstile and invokes a challenge redirect callback.
index.htmlView on unpkg · L178The obfuscated browser script resolves a destination and replaces the current page location.
index.htmlView on unpkg · L183The package declares index.html as its only published main file.
package.jsonView on unpkg · L2This report applies to ndmckauxuoincv@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML loads Cloudflare Turnstile and invokes a challenge redirect callback.
index.htmlView on unpkg · L9The HTML loads Cloudflare Turnstile and invokes a challenge redirect callback.
index.htmlView on unpkg · L178The obfuscated browser script resolves a destination and replaces the current page location.
index.htmlView on unpkg · L183The package declares index.html as its only published main file.
package.jsonView on unpkg · L2