The declared HTML entry contains heavily obscured browser code that obtains a remote-selected destination and redirects the visitor. The destination is not statically recoverable from the inspected source.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThis report applies to ndmctsgh_edu_tw@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
The page sends a built-in host key in a JSON request to an obscured remote endpoint.
The page decrypts a server-supplied value and treats it as a URL.
index.htmlView on unpkg · L183After its check, the page automatically starts a challenge or redirects the browser.
index.htmlView on unpkg · L183The package declares index.html as its only shipped main entry.
package.jsonView on unpkg · L2Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182The page sends a built-in host key in a JSON request to an obscured remote endpoint.
index.htmlView on unpkg · L183The page decrypts a server-supplied value and treats it as a URL.
index.htmlView on unpkg · L183After its check, the page automatically starts a challenge or redirects the browser.
index.htmlView on unpkg · L183A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe package declares index.html as its only shipped main entry.
package.jsonView on unpkg · L2