An npm preinstall hook runs an opaque loader before the package is available to the user. The loader combines hidden data with filesystem, decompression, and child-process capabilities.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest automatically runs preinstall.cjs during npm installation.
package.jsonView on unpkg · L5Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe preinstall hook is a 232 KB single-line obfuscated loader created with Function.
preinstall.cjsView on unpkg · L1The loader accesses filesystem, compression, and child-process modules to handle a hidden payload at install time.
preinstall.cjsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
preinstall.cjsView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
nebula.jsView on unpkgThis report applies to nebula-sdk@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest automatically runs preinstall.cjs during npm installation.
package.jsonView on unpkg · L5Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe preinstall hook is a 232 KB single-line obfuscated loader created with Function.
preinstall.cjsView on unpkg · L1The loader accesses filesystem, compression, and child-process modules to handle a hidden payload at install time.
preinstall.cjsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
preinstall.cjsView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
nebula.jsView on unpkg