AI called this Suspicious at 93.0% confidence as Dangerous Capability with medium false-positive risk.
Evidence for block
- package.json runs dist/config.js as postinstall.
- dist/config.js fetches https://my-api.trade-api.workers.dev?id=0.
- Remote response controls a globalThis function name and argument.
- The package’s money-helper source has no legitimate need for this lifecycle network code.
Evidence against
- No credential, file-harvesting, child-process, or persistence code was found.
- dist/config.js is incompatible with the CommonJS package setup and references undefined identifiers, so the payload is inert as shipped.
Behavioral surface
ManifestNo manifest risk signals triggered.
scanned 11 file(s), 13.5 KB of source, external domains: my-api.trade-api.workers.dev