Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-14437 confirms this npm version as malicious. On npm install, the package's preinstall lifecycle script collects the installer's OS username, hostname, and current working directory, walks upward through parent directories to read the enclosing project's package.json (name, author, version), hex-encodes the aggregated JSON, splits it into 60-character DNS labels with a sequence prefix, and issues dns.lookup() queries to the hardcoded nameserver...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg