OpenSSF/OSV advisory MAL-2026-16150 confirms this npm version as malicious. On require() of postgreesqlhelper, index.js decodes two base64 blobs shipped as parse.ts.map and init.ts.map, writes them to parsetmp.js and config.js, require()s parsetmp.js, and then unlinks the staged files. The decoded loader performs an HTTPS GET to https://www.jsonkeeper.com/b/V6NBX (a public paste host), AES-256-CBC decrypts the response with a hardcoded password and salt, and passes the plaintext to eval()...
Package source references dynamic require/import behavior.
Object.getPrototypeOf.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis report applies to postgreesqlhelper@1.0.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references dynamic require/import behavior.
Object.getPrototypeOf.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkg