OpenSSF/OSV advisory MAL-2026-14277 confirms this npm version as malicious. The package's main entry index.js imports child_process at the top of the file and invokes spawn("powershell",...) as a top-level side effect (line 27). Loading the module via require/import causes an unprompted PowerShell process to launch on the installer's machine, which is a Windows-focused code execution vector wholly unrelated to any legitimate library function...
This report applies to o0o9@2.0.2.
2.0.1, 1.0.0, 1.0.2, 1.0.4, 1.0.6, 1.0.8, 1.0.9, 1.2.1, 1.3.0, 1.8.1, 2.0.0, 2.0.2
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.