OpenSSF/OSV advisory MAL-2026-15997 confirms this npm version as malicious. The package impersonates the legitimate blakeembrey/node-helper library (matching author metadata, README, MIT license, and top-of-file helper functions) but appends a heavily obfuscated IIFE (obfuscator.io-style rotated string array with base64+URI decoder) that runs at require() time. The IIFE creates a hidden directory under os.homedir(), writes a second-stage obfuscated index.js and a synthesized package.json...
This report applies to node-helper@1.5.4.
1.5.4, 1.6.4
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.