High-performance web scraping automation and resilient HTTP fetch client SDK for Node.js
Importing the package or starting its CLI executes an opaque, encrypted payload through Node's VM. The payload runs with the importing process's module and require capabilities.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1Manifest entrypoint contains risky behavior absent from dist/build output.
bin/cli.jsView on unpkg · L15Package source references dynamic require/import behavior.
bin/cli.jsView on unpkg · L10A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis report applies to omnify-bypass@1.0.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
bin/cli.jsView on unpkg · L10Manifest entrypoint contains risky behavior absent from dist/build output.
bin/cli.jsView on unpkg · L15A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkg